Resource management error in Tor - CVE-2021-34549

 

Resource management error in Tor - CVE-2021-34549

Published: June 20, 2021


Vulnerability identifier: #VU54230
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34549
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the naive unkeyed hash function. A remote attacker can construct circuits with chosen circuit IDs, to create collisions and make the hash table inefficient, resulting in denial of service condition.


Affected software

Tor
Gentoo Linux
Arch Linux
Fedora
tor (Debian package)
tor

How to mitigate CVE-2021-34549

Install updates from vendor's website.

Tor - addressed in versions 0.3.5.15, 0.4.4.9, 0.4.5.9, 0.4.6.5
tor (Debian package) - update to 0.3.5.15-1
tor - addressed in versions 0.3.5.15-1.el7, 0.4.5.9-1.el8, 0.4.5.9-1.fc33, 0.4.5.9-1.fc34, 0.4.5.10-1.el8

External References

Related Security Bulletins