Bugzilla – Bug 1187322
VUL-0: CVE-2021-34548: tor: RELAY_END or RELAY_RESOLVED spoofing
Last modified: 2021-07-08 19:26:15 UTC
Fixed in tor 0.3.5.15, 0.4.4.9, 0.4.5.9, or 0.4.6.5 o Major bugfixes (security, backport from 0.4.6.5): - Don't allow relays to spoof RELAY_END or RELAY_RESOLVED cell on half-closed streams. Previously, clients failed to validate which hop sent these cells: this would allow a relay on a circuit to end a stream that wasn't actually built with it. Fixes bug 40389; bugfix on 0.3.5.1-alpha. This issue is also tracked as TROVE-2021- 003 and CVE-2021-34548. https://lists.torproject.org/pipermail/tor-announce/2021-June/000220.html https://lists.torproject.org/pipermail/tor-announce/2021-June/000221.html
This is an autogenerated message for OBS integration: This bug (1187322) was mentioned in https://build.opensuse.org/request/show/900011 Factory / tor https://build.opensuse.org/request/show/900012 15.2 / tor https://build.opensuse.org/request/show/900013 Backports:SLE-15-SP3 / tor https://build.opensuse.org/request/show/900014 Backports:SLE-15-SP2 / tor
openSUSE-SU-2021:0926-1: An update that solves three vulnerabilities and has three fixes is now available. Category: security (important) Bug References: 1179331,1181244,1187322,1187323,1187324,1187325 CVE References: CVE-2021-34548,CVE-2021-34549,CVE-2021-34550 JIRA References: Sources used: openSUSE Leap 15.2 (src): tor-0.4.5.9-lp152.2.12.1
openSUSE-SU-2021:0941-1: An update that solves three vulnerabilities and has three fixes is now available. Category: security (important) Bug References: 1179331,1181244,1187322,1187323,1187324,1187325 CVE References: CVE-2021-34548,CVE-2021-34549,CVE-2021-34550 JIRA References: Sources used: openSUSE Backports SLE-15-SP2 (src): tor-0.4.5.9-bp152.2.12.1
openSUSE-SU-2021:0989-1: An update that solves three vulnerabilities and has three fixes is now available. Category: security (important) Bug References: 1179331,1181244,1187322,1187323,1187324,1187325 CVE References: CVE-2021-34548,CVE-2021-34549,CVE-2021-34550 JIRA References: Sources used: openSUSE Backports SLE-15-SP3 (src): tor-0.4.5.9-bp153.2.3.1