CVE-2021-28090: Medium severity tor project tor vulnerability
Published Mar 19, 2021
·Updated
Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.
Affected Software
8 affected components
torproject Tor<0.3.5.14
torproject Tor>=0.4.4.4<0.4.4.8
torproject Tor>=0.4.5.0<0.4.5.7
torproject Tor=0.4.4.0-alpha
torproject Tor=0.4.4.1-alpha
torproject Tor=0.4.4.2-alpha
torproject Tor=0.4.4.3-alpha
Fedoraproject Fedora=33
Event History
Mar 19, 2021
CVE Published
via MITRE·04:19 AM
Data Sourced
via MITRE·04:19 AM
Description
Frequently Asked Questions
1
What is CVE-2021-28090?
CVE-2021-28090 is a vulnerability in Tor before 0.4.5.7 that allows a remote attacker to cause Tor directory authorities to exit with an assertion failure.
2
How does CVE-2021-28090 affect Tor?
CVE-2021-28090 affects Tor versions before 0.4.5.7.
3
What is the severity of CVE-2021-28090?
The severity of CVE-2021-28090 is medium with a CVSS score of 5.3.
4
How can I fix CVE-2021-28090?
To fix CVE-2021-28090, update Tor to version 0.4.5.7 or later.
5
Where can I find more information about CVE-2021-28090?
You can find more information about CVE-2021-28090 on the Tor Project blog, Tor Project bug tracker, and Tor Project GitLab.