CVE-2021-34549: High severity tor project tor vulnerability
An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen circuit ID to cause algorithm inefficiency.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34549?
CVE-2021-34549 is a vulnerability discovered in Tor before 0.4.6.5, which mishandles hashing for certain retrieval of circuit data, allowing an attacker to cause algorithm inefficiency.
What is the severity of CVE-2021-34549?
CVE-2021-34549 has a severity rating of 7.5 (High).
How does CVE-2021-34549 affect Torproject Tor?
CVE-2021-34549 affects Torproject Tor versions up to and including 0.4.6.5.
How can an attacker exploit CVE-2021-34549?
An attacker can exploit CVE-2021-34549 by triggering the use of an attacker-chosen circuit ID, leading to algorithm inefficiency.
How can I fix CVE-2021-34549?
To fix CVE-2021-34549, update Torproject Tor to version 0.4.6.6 or later.