CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
47.6%
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has
a heap-based buffer overflow when the digest final function sets a large
count value. It is recommended to upgrade to 1.9.1 or later.
git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=512c0c75276949f13b6373b5c04f7065af750b08
gnupg.org
launchpad.net/bugs/cve/CVE-2021-3345
lists.gnupg.org/pipermail/gnupg-announce/2021q1/000455.html
lists.gnupg.org/pipermail/gnupg-announce/2021q1/000456.html
nvd.nist.gov/vuln/detail/CVE-2021-3345
security-tracker.debian.org/tracker/CVE-2021-3345
www.cve.org/CVERecord?id=CVE-2021-3345
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
47.6%