Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 34: 2021-1b60c984e5 Critical: Tor Denial of Service Fix

fedora
Calendar Grey June 22, 2021
Dist Fedora Esm H88
The latest Tor release for Fedora 34 tackles essential vulnerabilities, boosting user privacy and safety while optimizing overall functionality.
update to latest upstream release - fix CVE-2021-34548, CVE-2021-34549, CVE-2021-34550

Summary

The Tor network is a group of volunteer-operated servers that allows people to

improve their privacy and security on the Internet. Tor's users employ this

network by connecting through a series of virtual tunnels rather than making a

direct connection, thus allowing both organizations and individuals to share

information over public networks without compromising their privacy. Along the

same line, Tor is an effective censorship circumvention tool, allowing its

users to reach otherwise blocked destinations or content. Tor can also be used

as a building block for software developers to create new communication tools

with built-in privacy features.

This package contains the Tor software that can act as either a server on the

Tor network, or as a client to connect to the Tor network.

update to latest upstream release - fix CVE-2021-34548, CVE-2021-34549,

CVE-2021-34550

[ 1 ] Bug #1972879 - CVE-2021-34548 tor: RELAY_END or RELAY_RESOLVED spoofing [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1972879

[ 2 ] Bug #1972882 - CVE-2021-34549 tor: hashtable-based CPU denial-of-service attack against relays [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1972882

[ 3 ] Bug #1972886 - CVE-2021-34550 tor: out-of-bounds memory access in v3 onion service descriptor parsing [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1972886

su -c 'dnf upgrade --advisory FEDORA-2021-1b60c984e5' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 34
Version: 0.4.5.9
Release: 1.fc34
Summary: Anonymizing overlay network for TCP

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here