CVE-2024-45192

Name
CVE-2024-45192
Description
An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/
https://gitlab.matrix.org/matrix-org/olm/
https://news.ycombinator.com/item?id=41249371
https://gitlab.matrix.org/matrix-org/olm/-/commit/6d4b5b07887821a95b144091c8497d09d377f985

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:matrix:olm:*:*:*:*:*:*:*:* olm >= 0 <= 3.2.6
cpe:2.3:a:matrix:olm:*:*:*:*:*:*:*:* olm >= None <= 3.2.16

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
olm edge-community 3.2.16-r1 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
olm edge-community 3.2.7-r2 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
olm 3.23-community 3.2.16-r1 Bart Ribbers <bribbers@disroot.org> possibly vulnerable
olm 3.22-community 3.2.16-r1 Bart Ribbers <bribbers@disroot.org> possibly vulnerable