An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor
| Software | From | Fixed in |
|---|---|---|
| torproject / tor | - | 0.3.5.15 |
| torproject / tor | 0.4.0.0 | 0.4.4.9 |
| torproject / tor | 0.4.5.0 | 0.4.5.9 |
| torproject / tor | 0.4.6.0 | 0.4.6.5 |