MGASA-2021-0180

Source
https://advisories.mageia.org/MGASA-2021-0180.html
Import Source
https://advisories.mageia.org/MGASA-2021-0180.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2021-0180
Related
Published
2021-04-12T19:59:59Z
Modified
2021-04-12T18:56:12Z
Summary
Updated tor packages fix security vulnerabilities
Details

The dump_desc() function that we used to dump unparseable information to disk, was called incorrectly in several places, in a way that could lead to excessive CPU usage (CVE-2021-28089).

A bug in appending detached signatures to a pending consensus document could be used to crash a directory authority (CVE-2021-28090).

References
Credits

Affected packages