Out-of-bounds read in Tor - CVE-2021-34550
Published: June 20, 2021
Vulnerability identifier: #VU54231
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34550
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition during v3 onion service descriptor parsing. A remote attacker can create an onion service descriptor that would crash any client that tried to visit it.
Affected software
Tor
Gentoo Linux
Arch Linux
Fedora
tor (Debian package)
tor
Gentoo Linux
Arch Linux
Fedora
tor (Debian package)
tor
How to mitigate CVE-2021-34550
Install updates from vendor's website.
Tor - addressed in versions 0.3.5.15, 0.4.4.9, 0.4.5.9, 0.4.6.5
tor (Debian package) - update to 0.3.5.15-1
tor - addressed in versions 0.3.5.15-1.el7, 0.4.5.9-1.el8, 0.4.5.9-1.fc33, 0.4.5.9-1.fc34, 0.4.5.10-1.el8
tor (Debian package) - update to 0.3.5.15-1
tor - addressed in versions 0.3.5.15-1.el7, 0.4.5.9-1.el8, 0.4.5.9-1.fc33, 0.4.5.9-1.fc34, 0.4.5.10-1.el8