Reachable Assertion in Tor - CVE-2021-28090
Published: March 17, 2021
Vulnerability identifier: #VU51542
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28090
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion in servers configured as directory authorities. A remote attacker can send specially crafted data to the server, trigger an assertions failure and crash it.
Affected software
Tor
Gentoo Linux
Fedora
tor (Debian package)
tor
Gentoo Linux
Fedora
tor (Debian package)
tor
How to mitigate CVE-2021-28090
Install updates from vendor's website.
Tor - addressed in versions 0.3.5.14, 0.4.4.8, 0.4.5.7
tor (Debian package) - update to 0.3.5.14-1
tor - addressed in versions 0.3.5.14-1.el7, 0.4.5.7-1.fc33
tor (Debian package) - update to 0.3.5.14-1
tor - addressed in versions 0.3.5.14-1.el7, 0.4.5.7-1.fc33