PT-2021-2516 · Tor+4 · Tor+4

Nick Mathewson

+1

·

Published

2019-05-07

·

Updated

2025-05-12

·

CVE-2021-28089

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tor versions prior to 0.4.5.7
Description The issue allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target. This is related to an error in the resource consumption control mechanism of the Tor browser's dump desc() function. Exploitation of this issue can lead to a denial of service.
Recommendations For versions prior to 0.4.5.7, update to version 0.4.5.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the Tor directory protocol to minimize the risk of exploitation.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1777
ALT-PU-2021-1492
ALT-PU-2025-6362
BDU:2021-01909
CVE-2021-28089
DSA-4871-1
MGASA-2021-0180
OPENSUSE-SU-2021:0461-1
OPENSUSE-SU-2021:0474-1
OPENSUSE-SU-2021_0461-1
OPENSUSE-SU-2024:11469-1
USN-5036-1

Affected Products

Alt Linux
Linuxmint
Suse
Tor
Ubuntu