PT-2021-2513 · Tor+4 · Tor+4

Nick Mathewson

+1

·

Published

2019-05-07

·

Updated

2025-05-12

·

CVE-2021-28090

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Tor versions prior to 0.4.5.7
Description The issue is related to the insufficient use of the assert() function in the dirvote add signatures to pending consensus() function of the Tor browser. This allows a remote attacker to cause Tor directory authorities to exit with an assertion failure.
Recommendations For versions prior to 0.4.5.7, update to version 0.4.5.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the dirvote add signatures to pending consensus() function until a patch is available.

Fix

Assertion Failure

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1777
ALT-PU-2021-1492
ALT-PU-2025-6362
BDU:2021-01891
CVE-2021-28090
DSA-4871-1
MGASA-2021-0180
OPENSUSE-SU-2021:0461-1
OPENSUSE-SU-2021:0474-1
OPENSUSE-SU-2021_0461-1
OPENSUSE-SU-2024:11469-1
USN-5036-1

Affected Products

Alt Linux
Linuxmint
Suse
Tor
Ubuntu