CVE-2010-1676
published 2010-12-22CVE-2010-1676: Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or…
PriorityP346critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.88%
94.0th percentile
Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.
Affected
149 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.2.1.26-6 (bookworm) | tor 0.2.1.26-6 (bookworm) |
| tor | tor | <= 0.2.1.1.27 | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-1676: tor - Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-al...
vendor_debian·2010·CVSS 10.0
CVE-2010-1676 [CRITICAL] CVE-2010-1676: tor - Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-al...
Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.2.1.26-6)
bullseye: resolved (fixed in 0.2.1.26-6)
forky: resolved (fixed in 0.2.1.26-6)
sid: resolved (fixed in 0.2.1.26-6)
trixie: resolved (fixed in 0.2.1.26-6)
GHSA
GHSA-pqjq-7p8q-hp58: Heap-based buffer overflow in Tor before 0
ghsa_unreviewed·2022-05-17
CVE-2010-1676 [HIGH] CWE-119 GHSA-pqjq-7p8q-hp58: Heap-based buffer overflow in Tor before 0
Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.
OSV
CVE-2010-1676: Heap-based buffer overflow in Tor before 0
osv·2010-12-22·CVSS 10.0
CVE-2010-1676 [CRITICAL] CVE-2010-1676: Heap-based buffer overflow in Tor before 0
Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
bugzilla·2011-01-20·CVSS 5.0
CVE-2011-0015 [MEDIUM] CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
epel-5 tracking bug for tor: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-1676
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=671259,665046
---
Adding parent bug CVE-2010-0383
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=671259,665046,557798
---
Adding parent bug 705192
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?
Bugzilla
CVE-2010-1676 Tor: Remotely exploitable heap-based buffer overflow
bugzilla·2010-12-22·CVSS 10.0
CVE-2010-1676 [CRITICAL] CVE-2010-1676 Tor: Remotely exploitable heap-based buffer overflow
CVE-2010-1676 Tor: Remotely exploitable heap-based buffer overflow
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1676 to
the following vulnerability:
Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before
0.2.2.20-alpha allows remote attackers to cause a denial of service
(daemon crash) or possibly execute arbitrary code via unspecified
vectors.
References:
[1] http://archives.seul.org/or/announce/Dec-2010/msg00000.html
[2] http://blog.torproject.org/blog/tor-02128-released-security-patches
[3] http://blog.torproject.org/blog/tor-02220-alpha-out-security-patches
[4] https://gitweb.torproject.org/tor.git/blob/release-0.2.1:/ChangeLog
[5] http://www.securityfocus.com/bid/45500
[6] http://securitytracker.com/id?1024910
[7] http://secunia.com/advisories/
Bugzilla
CVE-2010-1159 aircrack-ng: remote denial of service
bugzilla·2010-04-14·CVSS 6.8
CVE-2010-1159 [MEDIUM] CVE-2010-1159 aircrack-ng: remote denial of service
CVE-2010-1159 aircrack-ng: remote denial of service
A Debian bug report [1] notes an exploit for a security vulnerability in aircrack-ng has been published [2]. It also notes fixes in upstream SVN are available [3], [4].
As aircrack-ng is shipped in Fedora, this would affect Fedora 11, 12, 13, and rawhide.
This has been assigned CVE-2010-1159
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=577758
[2] http://pyrit.googlecode.com/svn/tags/opt/aircrackng_exploit.py
[3] http://trac.aircrack-ng.org/changeset/1676
[4] http://trac.aircrack-ng.org/changeset/1683
Discussion:
Created aircrack-ng tracking bugs for this issue
Affects: fedora-all [bug 582417]
---
Some more references:
upstream says that this also needs http://trac.aircrack-ng.org/changeset/1687 to be fixed, but the disco
http://archives.seul.org/or/announce/Dec-2010/msg00000.htmlhttp://blog.torproject.org/blog/tor-02128-released-security-patcheshttp://blog.torproject.org/blog/tor-02220-alpha-out-security-patcheshttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052657.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052690.htmlhttp://secunia.com/advisories/42536http://secunia.com/advisories/42667http://secunia.com/advisories/42783http://secunia.com/advisories/42916http://security.gentoo.org/glsa/glsa-201101-02.xmlhttp://securitytracker.com/id?1024910http://www.debian.org/security/2010/dsa-2136http://www.securityfocus.com/bid/45500http://www.vupen.com/english/advisories/2010/3290http://www.vupen.com/english/advisories/2011/0114https://gitweb.torproject.org/tor.git/blob/release-0.2.1:/ChangeLoghttp://archives.seul.org/or/announce/Dec-2010/msg00000.htmlhttp://blog.torproject.org/blog/tor-02128-released-security-patcheshttp://blog.torproject.org/blog/tor-02220-alpha-out-security-patcheshttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052657.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-December/052690.htmlhttp://secunia.com/advisories/42536http://secunia.com/advisories/42667http://secunia.com/advisories/42783http://secunia.com/advisories/42916http://security.gentoo.org/glsa/glsa-201101-02.xmlhttp://securitytracker.com/id?1024910http://www.debian.org/security/2010/dsa-2136http://www.securityfocus.com/bid/45500http://www.vupen.com/english/advisories/2010/3290http://www.vupen.com/english/advisories/2011/0114https://gitweb.torproject.org/tor.git/blob/release-0.2.1:/ChangeLog
2010-12-22
Published