Information disclosure in Tor - CVE-2021-34548
Published: June 20, 2021
Vulnerability identifier: #VU54229
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34548
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data. A remote attacker can spoof RELAY_END or RELAY_RESOLVED cell on half-closed streams, which would allow a relay on a circuit to end a stream that wasn't actually built with it.
Affected software
Tor
Gentoo Linux
Arch Linux
Fedora
tor (Debian package)
tor
Gentoo Linux
Arch Linux
Fedora
tor (Debian package)
tor
How to mitigate CVE-2021-34548
Install updates from vendor's website.
Tor - addressed in versions 0.3.5.15, 0.4.4.9, 0.4.5.9, 0.4.6.5
tor (Debian package) - update to 0.3.5.15-1
tor - addressed in versions 0.3.5.15-1.el7, 0.4.5.9-1.el8, 0.4.5.9-1.fc33, 0.4.5.9-1.fc34, 0.4.5.10-1.el8
tor (Debian package) - update to 0.3.5.15-1
tor - addressed in versions 0.3.5.15-1.el7, 0.4.5.9-1.el8, 0.4.5.9-1.fc33, 0.4.5.9-1.fc34, 0.4.5.10-1.el8