CVE-2021-34549
Gentoo Linux Security Advisory 202107-25
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen circuit ID to cause algorithm inefficiency.
Se ha detectado un problema en Tor versiones anteriores a 0.4.6.5, tambiƩn se conoce como TROVE-2021-005. Un hashing es manejado inapropiadamente para determinadas recuperaciones de datos del circuito. Consecuentemente, un atacante puede desencadenar un ID de circuito elegido por el atacante para causar ineficiencia en el algoritmo
Multiple security vulnerabilities were discovered in Tor, a connection-based low-latency anonymous communication system, which could result in denial of service or spoofing.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-06-10 CVE Reserved
- 2021-06-28 CVE Published
- 2024-08-04 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://gitlab.torproject.org/tpo/core/tor/-/issues/40391 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://blog.torproject.org/node/2041 | 2022-07-12 | |
https://security.gentoo.org/glsa/202107-25 | 2022-07-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | < 0.3.5.15 Search vendor "Torproject" for product "Tor" and version " < 0.3.5.15" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | >= 0.4.0.0 < 0.4.4.9 Search vendor "Torproject" for product "Tor" and version " >= 0.4.0.0 < 0.4.4.9" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | >= 0.4.5.0 < 0.4.5.9 Search vendor "Torproject" for product "Tor" and version " >= 0.4.5.0 < 0.4.5.9" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | >= 0.4.6.0 < 0.4.6.5 Search vendor "Torproject" for product "Tor" and version " >= 0.4.6.0 < 0.4.6.5" | - |
Affected
|