Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in Tor software could allow an attacker to cause a denial of service, with potential for more significant impact on directory authorities, though most Tor roles are only minorly affected. This issue arises from how the software handles specific signature types during parsing. The primary concern is confirming if our use of Tor aligns with these affected roles and assessing any exposure.
- Software flaw impacts how Tor handles certain signatures.
- Directory authorities face potential major impact; others minor.
- Confirm Tor usage and exposure within our environment.
Attack Path
How an attacker could exploit the issue
An attacker could target a Tor instance, such as a directory authority, by sending specially crafted consensus or detached signature data. This malformed data, when parsed by the vulnerable Tor software, could lead to an out-of-bounds write, potentially impacting the integrity and availability of the Tor network, particularly for directory authorities.
- Network access is required.
- Parsing unexpected signature data triggers the issue.
- Risk of network integrity compromise.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could affect Tor's ability to securely parse consensus or detached signature data. When parsing this data with an unexpected signature digest type, an out-of-bounds write may occur, potentially impacting the integrity and availability of the Tor service.
- Tor's integrity and availability.
- Parsing unexpected signature digest types.
- Service disruption or data corruption.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Tor Project is responsible for the Tor software. Owners of Tor instances, especially directory authorities, should prioritize identifying and assessing the risk of affected deployments.
- Own by Tor Project and instance operators.
- Verify Tor instance role and reachability.
- Update Tor to version 0.4.9.9 or later.