PT-2024-31476 · Matrix+1 · Libolm+1

Soatok

·

Published

2024-08-22

·

Updated

2024-09-10

·

CVE-2024-45193

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Matrix libolm versions 3.2.16 and earlier
Description There is Ed25519 signature malleability due to lack of validation criteria in the libolm implementation of Olm, which does not ensure that S < n. This issue only affects products that are no longer supported by the maintainer.
Recommendations For Matrix libolm versions 3.2.16 and earlier, consider switching to the successor effort vodozemac as soon as possible, as libolm has been officially deprecated by the Matrix Foundation. As a temporary workaround, consider restricting the use of the Ed25519 signature functionality until a more secure alternative is implemented.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2024-45193
RUSTSEC-2024-0368

Affected Products

Debian
Libolm