Out-of-bounds read in Tor - CVE-2021-34550

 

Out-of-bounds read in Tor - CVE-2021-34550

Published: June 20, 2021


Vulnerability identifier: #VU54231
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34550
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition during v3 onion service descriptor parsing. A remote attacker can create an onion service descriptor that would crash any client that tried to visit it.


Affected software

Tor
Gentoo Linux
Arch Linux
Fedora
tor (Debian package)
tor

How to mitigate CVE-2021-34550

Install updates from vendor's website.

Tor - addressed in versions 0.3.5.15, 0.4.4.9, 0.4.5.9, 0.4.6.5
tor (Debian package) - update to 0.3.5.15-1
tor - addressed in versions 0.3.5.15-1.el7, 0.4.5.9-1.el8, 0.4.5.9-1.fc33, 0.4.5.9-1.fc34, 0.4.5.10-1.el8

External References

Related Security Bulletins