5
CVSSv2

CVE-2021-38385

Published: 30/08/2021 Updated: 03/05/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Tor prior to 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

torproject tor

Vendor Advisories

Henry de Valence reported a flaw in the signature verification code in Tor, a connection-based low-latency anonymous communication system A remote attacker can take advantage of this flaw to cause an assertion failure, resulting in denial of service For the oldstable distribution (buster), this problem has been fixed in version 03516-1 For th ...
A remote denial of service issue has been fixed in tor >= 0467 An assertion failure could be caused by a behavior mismatch between the batch-signature verification code and the single-signature verification code This assertion failure could be triggered remotely, leading to a denial of service attack ...