CVE-2021-34549

Name
CVE-2021-34549
Description
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen circuit ID to cause algorithm inefficiency.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://gitlab.torproject.org/tpo/core/tor/-/issues/40391
CONFIRM https://blog.torproject.org/node/2041
Third Party Advisory https://security.gentoo.org/glsa/202107-25

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:* tor >= None < 0.3.5.15
cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:* tor >= 0.4.0.0 < 0.4.4.9
cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:* tor >= 0.4.5.0 < 0.4.5.9
cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:* tor >= 0.4.6.0 < 0.4.6.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
tor edge-community 0.4.5.7-r0 omni <omni+alpine@hack.org> possibly vulnerable
tor edge-community 0.4.2.7-r0 None possibly vulnerable
tor edge-community 0.3.5.8-r0 None possibly vulnerable
tor edge-community 0.3.2.10-r0 None possibly vulnerable
tor edge-community 0.3.0.8-r0 None possibly vulnerable
tor 3.22-community 0.4.5.7-r0 None possibly vulnerable
tor 3.22-community 0.4.2.7-r0 None possibly vulnerable
tor 3.22-community 0.3.5.8-r0 None possibly vulnerable
tor 3.22-community 0.3.2.10-r0 None possibly vulnerable
tor 3.22-community 0.3.0.8-r0 None possibly vulnerable