Reachable Assertion in Tor - CVE-2021-28090

 

Reachable Assertion in Tor - CVE-2021-28090

Published: March 17, 2021


Vulnerability identifier: #VU51542
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28090
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion in servers configured as directory authorities. A remote attacker can send specially crafted data to the server, trigger an assertions failure and crash it.


Affected software

Tor
Gentoo Linux
Fedora
tor (Debian package)
tor

How to mitigate CVE-2021-28090

Install updates from vendor's website.

Tor - addressed in versions 0.3.5.14, 0.4.4.8, 0.4.5.7
tor (Debian package) - update to 0.3.5.14-1
tor - addressed in versions 0.3.5.14-1.el7, 0.4.5.7-1.fc33

External References

Related Security Bulletins