PT-2021-4123 · Tor+4 · Tor+4

Sergei Glazunov

·

Published

2021-06-16

·

Updated

2025-05-12

·

CVE-2021-34550

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tor versions prior to 0.4.6.5
Description The issue is related to the v3 onion service descriptor parsing, which allows out-of-bounds memory access and can cause a client crash via a crafted onion service descriptor. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For versions prior to 0.4.6.5, update to version 0.4.6.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of v3 onion services until a patch is applied.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2008
ALT-PU-2025-6362
BDU:2021-04714
CVE-2021-34550
DSA-4932-1
MGASA-2021-0293
OPENSUSE-SU-2021:0926-1
OPENSUSE-SU-2021:0941-1
OPENSUSE-SU-2021_0926-1
OPENSUSE-SU-2024:11469-1
USN-5036-1

Affected Products

Alt Linux
Linuxmint
Suse
Tor
Ubuntu