Resource exhaustion in Tor - CVE-2021-28089
Published: March 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing directory data. A remote attacker can force the Tor instance do consume huge amounts of CPU resources and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Fedora
tor (Debian package)
tor
How to mitigate CVE-2021-28089
tor (Debian package) - update to 0.3.5.14-1
tor - addressed in versions 0.3.5.14-1.el7, 0.4.5.7-1.fc33