CVE-2021-34549
29.06.2021, 12:15
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen circuit ID to cause algorithm inefficiency.Enginsight
| Vendor | Product | Version |
|---|---|---|
| torproject | tor | 𝑥 < 0.3.5.15 |
| torproject | tor | 0.4.0.0 ≤ 𝑥 < 0.4.4.9 |
| torproject | tor | 0.4.5.0 ≤ 𝑥 < 0.4.5.9 |
| torproject | tor | 0.4.6.0 ≤ 𝑥 < 0.4.6.5 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| tor |
|