Circuit Data Hashing Mismanagement in Tor by The Tor Project
CVE-2021-34549
7.5HIGH
What is CVE-2021-34549?
A flaw was identified in the Tor software, specifically impacting versions before 0.4.6.5. This vulnerability arises from the mishandling of hashing during the retrieval of circuit data, allowing an attacker to leverage an attacker-chosen circuit ID. This may lead to persistent algorithm inefficiencies that could be exploited in various ways. It is crucial for users of Tor to apply the relevant patches to mitigate potential risks associated with this vulnerability.
