CVE-2021-38385: High severity torproject Tor vulnerability
Published Aug 30, 2021
·Updated
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.
Affected Software
3 affected components
torproject Tor<0.3.5.16
torproject Tor>=0.4.0.0<0.4.5.10
torproject Tor>=0.4.6.0<0.4.6.7
Event History
Aug 30, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-38385?
CVE-2021-38385 is a vulnerability in Tor versions before 0.3.5.16, 0.4.5.10, and 0.4.6.7 that mishandles batch-signature verification, leading to a remote assertion failure.
2
How severe is CVE-2021-38385?
CVE-2021-38385 has a severity score of 7.5 (high).
3
Which software versions are affected by CVE-2021-38385?
CVE-2021-38385 affects Tor versions before 0.3.5.16, 0.4.5.10, and 0.4.6.7.
4
What is the Common Weakness Enumeration (CWE) for CVE-2021-38385?
The CWE for CVE-2021-38385 is CWE-617.
5
Where can I find more information about CVE-2021-38385?
You can find more information about CVE-2021-38385 on the Tor Project's blog and bug tracker.