Henry de Valence reported a flaw in the signature verification code in Tor,
a connection-based low-latency anonymous communication system. A remote
attacker can take advantage of this flaw to cause an assertion failure,
resulting in denial of service.
- https://bugs.mageia.org/show_bug.cgi?id=29377
- https://blog.torproject.org/new-stable-releases-tor-03516-04510-and-0467/
-
- https://www.cve.org/CVERecord?id=CVE-2021-38385
- 8/core/tor-0.3.5.16-1.mga8
Get the latest Linux and open source security news straight to your inbox.