PT-2024-31475 · Unknown+1 · Matrix Libolm+1

Soatok

·

Published

2024-08-22

·

Updated

2024-09-10

·

CVE-2024-45192

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Matrix libolm versions through 3.2.16
Description An issue was discovered in Matrix libolm, where cache-timing attacks can occur due to the use of base64 when decoding group session keys. This vulnerability only affects products that are no longer supported by the maintainer.
Recommendations For Matrix libolm versions through 3.2.16, consider switching to vodozemac as soon as possible, as it is the successor effort to libolm and is written in Rust. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2024-45192
RUSTSEC-2024-0368

Affected Products

Debian
Matrix Libolm