Circuit Data Hashing Mismanagement in Tor by The Tor Project
CVE-2021-34549

7.5HIGH

Key Information:

Vendor

Torproject

Status
Vendor
CVE Published:
29 June 2021

What is CVE-2021-34549?

A flaw was identified in the Tor software, specifically impacting versions before 0.4.6.5. This vulnerability arises from the mishandling of hashing during the retrieval of circuit data, allowing an attacker to leverage an attacker-chosen circuit ID. This may lead to persistent algorithm inefficiencies that could be exploited in various ways. It is crucial for users of Tor to apply the relevant patches to mitigate potential risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.