Related Vulnerabilities: CVE-2021-34550  

A security issue has been found in Tor before version 0.4.5.9. An out-of-bounds memory access in the v3 onion service descriptor parsing could be exploited by crafting an onion service descriptor that would crash any client that tried to visit it.

Severity Low

Remote Yes

Type Denial of service

Description

A security issue has been found in Tor before version 0.4.5.9. An out-of-bounds memory access in the v3 onion service descriptor parsing could be exploited by crafting an onion service descriptor that would crash any client that tried to visit it.

AVG-2075 tor 0.4.5.8-2 0.4.5.9-1 Medium Fixed

https://blog.torproject.org/node/2041
https://gitlab.torproject.org/tpo/core/tor/-/issues/40392
https://gitlab.torproject.org/tpo/core/tor/-/commit/f57b5c48e0aa01acd84a194fe4657a0d1cee04cf