Oval Definition:oval:org.opensuse.security:def:202144538
Revision Date:2022-09-02Version:1
Title:CVE-2021-44538
Description:

The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to manipulate the state of the receiver's session in such a way that, for some buffer sizes, a buffer overflow happens on a call to olm_session_describe. Furthermore, safe buffer sizes were undocumented. The overflow content is partially controllable by the attacker and limited to ASCII spaces and digits. The known affected products are Element Web And SchildiChat Web.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2021-44538
SUSE CVE-2021-44538
SUSE-SU-2022:0058-1
openSUSE-SU-2022:0058-1
Platform(s):openSUSE Leap 15.3
openSUSE Leap 15.4
openSUSE Tumbleweed
SUSE Linux Enterprise Desktop 15 SP2
SUSE Linux Enterprise Desktop 15 SP3
SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15 SP4
SUSE Linux Enterprise Workstation Extension 15 SP2
SUSE Linux Enterprise Workstation Extension 15 SP3
SUSE Linux Enterprise Workstation Extension 15 SP4
Product(s):
Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • MozillaThunderbird-91.4.1-1.1 is installed
  • OR MozillaThunderbird-translations-common-91.4.1-1.1 is installed
  • OR MozillaThunderbird-translations-other-91.4.1-1.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.3 is installed
  • AND Package Information
  • MozillaThunderbird-91.4.1-8.48.1 is installed
  • AND MozillaThunderbird is signed with openSUSE key
  • OR
  • MozillaThunderbird-translations-common-91.4.1-8.48.1 is installed
  • AND MozillaThunderbird-translations-common is signed with openSUSE key
  • OR
  • MozillaThunderbird-translations-other-91.4.1-8.48.1 is installed
  • AND MozillaThunderbird-translations-other is signed with openSUSE key
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP3 is installed
  • OR SUSE Linux Enterprise Server 15 SP3 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
  • OR SUSE Linux Enterprise Workstation Extension 15 SP3 is installed
  • AND Package Information
  • MozillaThunderbird-91.4.1-8.48.1 is installed
  • OR MozillaThunderbird-translations-common-91.4.1-8.48.1 is installed
  • OR MozillaThunderbird-translations-other-91.4.1-8.48.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP2 is installed
  • OR SUSE Linux Enterprise Server 15 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • OR SUSE Linux Enterprise Workstation Extension 15 SP2 is installed
  • AND MozillaThunderbird is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP2 is installed
  • OR SUSE Linux Enterprise Server 15 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • OR SUSE Linux Enterprise Workstation Extension 15 SP2 is installed
  • AND MozillaThunderbird is affected
  • OR Package Information
  • SUSE Linux Enterprise Desktop 15 SP3 is installed
  • OR SUSE Linux Enterprise Server 15 SP3 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP3 is installed
  • OR SUSE Linux Enterprise Workstation Extension 15 SP3 is installed
  • AND
  • MozillaThunderbird-91.4.1-8.48.1 is installed
  • OR MozillaThunderbird-translations-common-91.4.1-8.48.1 is installed
  • OR MozillaThunderbird-translations-other-91.4.1-8.48.1 is installed
  • Definition Synopsis
  • openSUSE Leap 15.4 is installed
  • AND Package Information
  • MozillaThunderbird-91.8.0-150200.8.65.1 is installed
  • AND MozillaThunderbird is signed with openSUSE key
  • OR
  • MozillaThunderbird-translations-common-91.8.0-150200.8.65.1 is installed
  • AND MozillaThunderbird-translations-common is signed with openSUSE key
  • OR
  • MozillaThunderbird-translations-other-91.8.0-150200.8.65.1 is installed
  • AND MozillaThunderbird-translations-other is signed with openSUSE key
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP4 is installed
  • OR SUSE Linux Enterprise Server 15 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
  • OR SUSE Linux Enterprise Workstation Extension 15 SP4 is installed
  • AND Package Information
  • MozillaThunderbird-91.8.0-150200.8.65.1 is installed
  • OR MozillaThunderbird-translations-common-91.8.0-150200.8.65.1 is installed
  • OR MozillaThunderbird-translations-other-91.8.0-150200.8.65.1 is installed
  • BACK