Vulnerability Description
SerenityOS Unspecified is affected by: Buffer Overflow. The impact is: obtain sensitive information (context-dependent). The component is: /Userland/Libraries/LibCrypto/ASN1/DER.h Crypto::der_decode_sequence() function. The attack vector is: Parsing RSA Key ASN.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Serenityos | Serenityos | - |
Related Weaknesses (CWE)
References
- https://github.com/SerenityOS/serenity/commit/48fbf6a88d4822a1e5470cf08f29464511PatchThird Party Advisory
- https://github.com/SerenityOS/serenity/issues/5317Third Party Advisory
- https://github.com/SerenityOS/serenity/pull/5344Third Party Advisory
- https://github.com/SerenityOS/serenity/commit/48fbf6a88d4822a1e5470cf08f29464511PatchThird Party Advisory
- https://github.com/SerenityOS/serenity/issues/5317Third Party Advisory
- https://github.com/SerenityOS/serenity/pull/5344Third Party Advisory
FAQ
What is CVE-2021-27343?
CVE-2021-27343 is a vulnerability with a CVSS score of 7.5 (HIGH). SerenityOS Unspecified is affected by: Buffer Overflow. The impact is: obtain sensitive information (context-dependent). The component is: /Userland/Libraries/LibCrypto/ASN1/DER.h Crypto::der_decode_s...
How severe is CVE-2021-27343?
CVE-2021-27343 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27343?
Check the references section above for vendor advisories and patch information. Affected products include: Serenityos Serenityos.