An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
Link | Tags |
---|---|
https://gitlab.torproject.org/tpo/core/tor/-/issues/40392 | broken link |
https://blog.torproject.org/node/2041 | release notes vendor advisory |
https://security.gentoo.org/glsa/202107-25 | third party advisory vendor advisory |