Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 8: 2021-0426 Moderate: Tor Denial Of Service Issue

mageia
Calendar Grey September 23, 2021
Dist Mageia Esm H88
Mageia has released updates for its tor packages to mitigate a significant vulnerability that leads to potential denial of service attacks, which was disclosed on September 23, 2021.
Henry de Valence reported a flaw in the signature verification code in Tor, a connection-based low-latency anonymous communication system

Summary

Henry de Valence reported a flaw in the signature verification code in Tor, a connection-based low-latency anonymous communication system. A remote attacker can take advantage of this flaw to cause an assertion failure, resulting in denial of service.

References

- https://bugs.mageia.org/show_bug.cgi?id=29377

- https://blog.torproject.org/new-stable-releases-tor-03516-04510-and-0467/

-

- https://www.cve.org/CVERecord?id=CVE-2021-38385

Resolution

SRPMS

- 8/core/tor-0.3.5.16-1.mga8

Publication date: 23 Sep 2021
URL: https://advisories.mageia.org/MGASA-2021-0426.html
Type: security
CVE: CVE-2021-38385

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here