Back to Database
Status published
High
CVE-2021-3345
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based...
Vulnerability Description
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3345
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git%3Ba=commit%3Bh=512c0c75276949f13b6373b5c04f7065af750b08
- https://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000455.html
- https://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000456.html
- https://gnupg.org
- https://bugs.gentoo.org/show_bug.cgi?id=767814
- https://www.oracle.com//security-alerts/cpujul2021.html
More from gnupg
View All →CVE-2022-47629
Libksba before 1.6.3 is prone to an integer overflow vulnerability...
Unknown
0
CVE-2022-34903
GnuPG through 2.3.6, in unusual situations where an attacker possesses...
Medium
6.5
CVE-2021-40528
The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery...
Unknown
0
CVE-2021-33560
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption...
Unknown
0
CVE-2020-25125
GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array...
High
7.8
Affected Vendor
gnupg
View all reports →Affected Software
libgcrypt, communications billing and revenue management
Vulnerable Versions:
1.9.0, 12.0.0.3.0
Timeline
Official Publish:
January 29th, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.