CVE-2021-3345
HIGHLibgcrypt 1.9.0 - Heap-Based Buffer Overflow in _gcry_md_block_write
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2021-3345. PoCs published by MLGRadish, SpiralBL0CK.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2021-3345, a vulnerability in Libgcrypt 1.9.0. The exploit leverages a buffer overflow in the gcry_md_write function to achieve arbitrary code execution by overwriting a function pointer.
Description
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.
Exploits (2)
This repository contains a functional exploit for CVE-2021-3345, a vulnerability in Libgcrypt 1.9.0. The exploit leverages a buffer overflow in the gcry_md_write function to achieve arbitrary code execution by overwriting a function pointer.
This repository contains a functional exploit for CVE-2021-3345, a heap-based buffer overflow in Libgcrypt 1.9.0. The exploit manipulates the `gcry_md_block_ctx` structure to achieve arbitrary code execution by overwriting a function pointer, leading to a shell spawn.
References (6)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H