Buffer Overflow Vulnerability in SerenityOS Affects LibCrypto
CVE-2021-27343

7.5HIGH

Key Information:

Vendor

Serenityos

Vendor
CVE Published:
6 April 2021

What is CVE-2021-27343?

A buffer overflow vulnerability exists within the LibCrypto component of SerenityOS, specifically in the Crypto::der_decode_sequence() function. This issue can be exploited during the parsing of RSA Key ASN.1 structures, potentially allowing attackers to access sensitive information dependent on the context of the attack. It is crucial for users and administrators to apply mitigation strategies to safeguard against potential exploitation.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.