First published: Fri Mar 19 2021(Updated: )
Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Torproject Tor | <0.3.5.14 | |
Torproject Tor | >=0.4.4.4<0.4.4.8 | |
Torproject Tor | >=0.4.5.0<0.4.5.7 | |
Torproject Tor | =0.4.4.0-alpha | |
Torproject Tor | =0.4.4.1-alpha | |
Torproject Tor | =0.4.4.2-alpha | |
Torproject Tor | =0.4.4.3-alpha | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28090 is a vulnerability in Tor before 0.4.5.7 that allows a remote attacker to cause Tor directory authorities to exit with an assertion failure.
CVE-2021-28090 affects Tor versions before 0.4.5.7.
The severity of CVE-2021-28090 is medium with a CVSS score of 5.3.
To fix CVE-2021-28090, update Tor to version 0.4.5.7 or later.
You can find more information about CVE-2021-28090 on the Tor Project blog, Tor Project bug tracker, and Tor Project GitLab.