CVE-2009-0939
published 2009-03-18CVE-2009-0939: Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using…
PriorityP429critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.05%
79.1th percentile
Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.2.0.34-1 (bookworm) | tor 0.2.0.34-1 (bookworm) |
| tor | tor | <= 0.2.0.33 | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2009-0939: tor - Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown...
vendor_debian·2009·CVSS 10.0
CVE-2009-0939 [CRITICAL] CVE-2009-0939: tor - Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown...
Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0.
Scope: local
bookworm: resolved (fixed in 0.2.0.34-1)
bullseye: resolved (fixed in 0.2.0.34-1)
forky: resolved (fixed in 0.2.0.34-1)
sid: resolved (fixed in 0.2.0.34-1)
trixie: resolved (fixed in 0.2.0.34-1)
Red Hat
tor: multiple security fixes in 0.2.0.34 (CVE-2009-0936, CVE-2009-0937, CVE-2009-0938, CVE-2009-0939)
vendor_redhat·CVSS 5.0
CVE-2009-0938 [MEDIUM] tor: multiple security fixes in 0.2.0.34 (CVE-2009-0936, CVE-2009-0937, CVE-2009-0938, CVE-2009-0939)
tor: multiple security fixes in 0.2.0.34 (CVE-2009-0936, CVE-2009-0937, CVE-2009-0938, CVE-2009-0939)
Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service (exit node crash) via "malformed input."
Red Hat
tor: multiple security fixes in 0.2.0.34 (CVE-2009-0936, CVE-2009-0937, CVE-2009-0938, CVE-2009-0939)
vendor_redhat·CVSS 5.0
CVE-2009-0937 [MEDIUM] tor: multiple security fixes in 0.2.0.34 (CVE-2009-0936, CVE-2009-0937, CVE-2009-0938, CVE-2009-0939)
tor: multiple security fixes in 0.2.0.34 (CVE-2009-0936, CVE-2009-0937, CVE-2009-0938, CVE-2009-0939)
Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service via unknown vectors.
Red Hat
tor: multiple security fixes in 0.2.0.34 (CVE-2009-0936, CVE-2009-0937, CVE-2009-0938, CVE-2009-0939)
vendor_redhat·CVSS 5.0
CVE-2009-0936 [MEDIUM] tor: multiple security fixes in 0.2.0.34 (CVE-2009-0936, CVE-2009-0937, CVE-2009-0938, CVE-2009-0939)
tor: multiple security fixes in 0.2.0.34 (CVE-2009-0936, CVE-2009-0937, CVE-2009-0938, CVE-2009-0939)
Unspecified vulnerability in Tor before 0.2.0.34 allows attackers to cause a denial of service (infinite loop) via "corrupt votes."
Red Hat
tor: multiple security fixes in 0.2.0.34 (CVE-2009-0936, CVE-2009-0937, CVE-2009-0938, CVE-2009-0939)
vendor_redhat·CVSS 5.0
CVE-2009-0939 [MEDIUM] tor: multiple security fixes in 0.2.0.34 (CVE-2009-0936, CVE-2009-0937, CVE-2009-0938, CVE-2009-0939)
tor: multiple security fixes in 0.2.0.34 (CVE-2009-0936, CVE-2009-0937, CVE-2009-0938, CVE-2009-0939)
Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0.
GHSA
GHSA-4v97-9crm-p348: Tor before 0
ghsa_unreviewed·2022-05-02
CVE-2009-0939 [HIGH] GHSA-4v97-9crm-p348: Tor before 0
Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0.
OSV
CVE-2009-0939: Tor before 0
osv·2009-03-18·CVSS 10.0
CVE-2009-0939 [CRITICAL] CVE-2009-0939: Tor before 0
Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0.
No detection rules found.
No public exploits indexed.
http://archives.seul.org/or/announce/Feb-2009/msg00000.htmlhttp://secunia.com/advisories/33880http://secunia.com/advisories/34583http://security.gentoo.org/glsa/glsa-200904-11.xmlhttp://www.securityfocus.com/bid/33713http://archives.seul.org/or/announce/Feb-2009/msg00000.htmlhttp://secunia.com/advisories/33880http://secunia.com/advisories/34583http://security.gentoo.org/glsa/glsa-200904-11.xmlhttp://www.securityfocus.com/bid/33713
2009-03-18
Published