CVE-2021-28089: High severity tor project tor vulnerability
Published Mar 19, 2021
·Updated
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
Affected Software
8 affected components
torproject Tor<0.3.5.14
torproject Tor>=0.4.4.4<0.4.4.8
torproject Tor>=0.4.5.0<0.4.5.7
torproject Tor=0.4.4.0-alpha
torproject Tor=0.4.4.1-alpha
torproject Tor=0.4.4.2-alpha
torproject Tor=0.4.4.3-alpha
Fedoraproject Fedora=33
Event History
Mar 19, 2021
CVE Published
via MITRE·04:18 AM
Data Sourced
via MITRE·04:18 AM
Description
Frequently Asked Questions
1
What is CVE-2021-28089?
CVE-2021-28089 is a vulnerability in Tor before version 0.4.5.7 that allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target.
2
What is the severity of CVE-2021-28089?
The severity of CVE-2021-28089 is high with a CVSS score of 7.5.
3
What software versions are affected by CVE-2021-28089?
Versions of Tor up to and including 0.3.5.14, 0.4.4.4 to 0.4.4.8, and 0.4.5.0 to 0.4.5.7 are affected by CVE-2021-28089.
4
How can a remote participant exhaust CPU resources on a target using CVE-2021-28089?
A remote participant in the Tor directory protocol can exhaust CPU resources on a target by exploiting the vulnerability in Tor before version 0.4.5.7.
5
How can I fix CVE-2021-28089?
To fix CVE-2021-28089, update Tor to version 0.4.5.7 or later.