CVE-2024-45192

An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Configurations

No configuration.

History

10 Sep 2024, 19:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.3

01 Sep 2024, 22:15

Type Values Removed Values Added
Summary (en) An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. (en) An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

28 Aug 2024, 19:15

Type Values Removed Values Added
Summary (en) An issue was discovered in Matrix libolm (aka Olm) through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. (en) An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

23 Aug 2024, 16:18

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Matrix libolm (también conocido como Olm) hasta la versión 3.2.16. Los ataques de sincronización de caché pueden ocurrir debido al uso de base64 al decodificar claves de sesión grupal. NOTA: Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el fabricante.

22 Aug 2024, 19:35

Type Values Removed Values Added
CWE CWE-385
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

22 Aug 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-22 16:15

Updated : 2024-09-10 19:35


NVD link : CVE-2024-45192

Mitre link : CVE-2024-45192

CVE.ORG link : CVE-2024-45192


JSON object : View

Products Affected

No product.

CWE
CWE-385

Covert Timing Channel