First published: Mon Aug 30 2021(Updated: )
Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Torproject Tor | <0.3.5.16 | |
Torproject Tor | >=0.4.0.0<0.4.5.10 | |
Torproject Tor | >=0.4.6.0<0.4.6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38385 is a vulnerability in Tor versions before 0.3.5.16, 0.4.5.10, and 0.4.6.7 that mishandles batch-signature verification, leading to a remote assertion failure.
CVE-2021-38385 has a severity score of 7.5 (high).
CVE-2021-38385 affects Tor versions before 0.3.5.16, 0.4.5.10, and 0.4.6.7.
The CWE for CVE-2021-38385 is CWE-617.
You can find more information about CVE-2021-38385 on the Tor Project's blog and bug tracker.