Skip to content

olm-sys: wrapped library unmaintained, potentially vulnerable

High severity GitHub Reviewed Published Sep 3, 2024 to the GitHub Advisory Database • Updated Sep 3, 2024

Package

cargo olm-sys (Rust)

Affected versions

<= 1.3.2

Patched versions

None

Description

After several cryptographic vulnerabilities in libolm were disclosed publicly, the Matrix Foundation has officially deprecated the library. olm-sys is a thin wrapper around libolm and is now deprecated and potentially vulnerable in kind.

Users of olm-sys and its higher-level abstraction, olm-rs, are highly encouraged to switch to vodozemac as soon as possible. It is the successor effort to libolm and is written in Rust.

References

Published to the GitHub Advisory Database Sep 3, 2024
Reviewed Sep 3, 2024
Last updated Sep 3, 2024

Severity

High

Weaknesses

CVE ID

No known CVE

GHSA ID

GHSA-p2q9-36vw-c468
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.