Tor update with vulnerability fixes

Corrective releases of the Tor toolkit (0.3.5.14, 0.4.4.8, 0.4.5.7) used for organizing the operation of the anonymous Tor network have been released. The new versions fix two vulnerabilities that can be exploited to conduct DoS attacks on nodes in the Tor network:

  • CVE-2021-28089 — an attacker can cause a denial of service for any Tor nodes and clients by creating a heavy CPU load resulting from processing certain types of data. This vulnerability poses the greatest risk to relays and servers directory authorities, which are connection points to the network responsible for authentication and delivering the user a list of gateways handling traffic. Directory servers are the easiest targets for attack, as they allow data loading by any participant. An attack on relays and clients can be organized through loading the directory cache.
  • CVE-2021-28090 — an attacker can cause a crash of server directory authorities by sending specially crafted detached signatures used to convey consensus state information within the network.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster