CVE-2021-3345
published 2021-01-29CVE-2021-3345: _gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.06%
60.7th percentile
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libgcrypt20 | — | — |
| gnupg | libgcrypt | — | — |
| oracle | communications_billing_and_revenue_management | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Accounts Receivable (libgcrypt) — CVE-2021-3345
vendor_oracle·2021-07-15·CVSS 7.8
CVE-2021-3345 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Accounts Receivable (libgcrypt) — CVE-2021-3345
Oracle Oracle Communications Applications Risk Matrix: Accounts Receivable (libgcrypt) vulnerability
CVE: CVE-2021-3345
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujul2021 (JUL 2021)
Red Hat
libgcrypt: Heap buffer overflow in the block buffer management code
vendor_redhat·2021-01-29·CVSS 7.8
CVE-2021-3345 [HIGH] CWE-191 libgcrypt: Heap buffer overflow in the block buffer management code
libgcrypt: Heap buffer overflow in the block buffer management code
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.
A flaw was found in libgcrypt. A heap-based buffer overflow in the block buffer management code may lead to memory corruption before any verification is made or signature is validated. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: No Red Hat products are affected by this flaw, as the vulnerable version of libgcrypt (1.9.0) has not been shipped in any products.
Package: libgcrypt (Red Hat Enterprise Linux 6) - Not affected
Package: l
Debian
CVE-2021-3345: libgcrypt20 - _gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a he...
vendor_debian·2021·CVSS 7.8
CVE-2021-3345 [HIGH] CVE-2021-3345: libgcrypt20 - _gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a he...
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-pf53-rq8f-rwqx: _gcry_md_block_write in cipher/hash-common
ghsa_unreviewed·2022-05-24
CVE-2021-3345 [HIGH] CWE-787 GHSA-pf53-rq8f-rwqx: _gcry_md_block_write in cipher/hash-common
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt before 1.9.1 has a heap-based buffer overflow when the digest final function sets a large count value.
OSV
CVE-2021-3345: _gcry_md_block_write in cipher/hash-common
osv·2021-01-29·CVSS 7.8
CVE-2021-3345 [HIGH] CVE-2021-3345: _gcry_md_block_write in cipher/hash-common
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.
No detection rules found.
No public exploits indexed.
https://bugs.gentoo.org/show_bug.cgi?id=767814https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=512c0c75276949f13b6373b5c04f7065af750b08https://gnupg.orghttps://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000455.htmlhttps://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000456.htmlhttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://bugs.gentoo.org/show_bug.cgi?id=767814https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=512c0c75276949f13b6373b5c04f7065af750b08https://gnupg.orghttps://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000455.htmlhttps://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000456.htmlhttps://www.oracle.com//security-alerts/cpujul2021.html
2021-01-29
Published