CVE-2011-0493
published 2011-01-19CVE-2011-0493: Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors…
PriorityP418medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.52%
83.1th percentile
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors related to malformed router caches and improper handling of integer values.
Affected
191 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.2.1.29-1 (bookworm) | tor 0.2.1.29-1 (bookworm) |
| tor | tor | <= 0.2.1.28 | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2011-0493: tor - Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attacke...
vendor_debian·2011·CVSS 5.0
CVE-2011-0493 [MEDIUM] CVE-2011-0493: tor - Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attacke...
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors related to malformed router caches and improper handling of integer values.
Scope: local
bookworm: resolved (fixed in 0.2.1.29-1)
bullseye: resolved (fixed in 0.2.1.29-1)
forky: resolved (fixed in 0.2.1.29-1)
sid: resolved (fixed in 0.2.1.29-1)
trixie: resolved (fixed in 0.2.1.29-1)
GHSA
GHSA-r4gp-h7pq-qx3w: Tor before 0
ghsa_unreviewed·2022-05-17
CVE-2011-0493 [MEDIUM] GHSA-r4gp-h7pq-qx3w: Tor before 0
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors related to malformed router caches and improper handling of integer values.
OSV
CVE-2011-0493: Tor before 0
osv·2011-01-19·CVSS 5.0
CVE-2011-0493 [MEDIUM] CVE-2011-0493: Tor before 0
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors related to malformed router caches and improper handling of integer values.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 tor: multiple security flaws fixed in 0.2.1.29
bugzilla·2011-01-20·CVSS 5.0
CVE-2011-0015 [MEDIUM] CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 tor: multiple security flaws fixed in 0.2.1.29
CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 tor: multiple security flaws fixed in 0.2.1.29
Tor 0.2.1.29 fixes a number of security flaws, as noted below:
http://blog.torproject.org/blog/tor-02129-released-security-patches
https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLog
The specifics of the CVEs are as follows:
* Name: CVE-2011-0015
* Reference: https://trac.torproject.org/projects/tor/ticket/2324
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not
properly check the amount of compression in zlib-compressed data,
which allows remote attackers to cause a denial of service via a large
compression factor.
* Name: CVE-2011-0016
* Reference: https://trac.torproject.org/projects/tor/ticket/2384
Bugzilla
CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
bugzilla·2011-01-20·CVSS 5.0
CVE-2011-0015 [MEDIUM] CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
epel-5 tracking bug for tor: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-1676
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=671259,665046
---
Adding parent bug CVE-2010-0383
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=671259,665046,557798
---
Adding parent bug 705192
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?
http://archives.seul.org/or/announce/Jan-2011/msg00000.htmlhttp://blog.torproject.org/blog/tor-02129-released-security-patcheshttp://www.securityfocus.com/bid/45953https://exchange.xforce.ibmcloud.com/vulnerabilities/64864https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLoghttps://trac.torproject.org/projects/tor/ticket/2352http://archives.seul.org/or/announce/Jan-2011/msg00000.htmlhttp://blog.torproject.org/blog/tor-02129-released-security-patcheshttp://www.securityfocus.com/bid/45953https://exchange.xforce.ibmcloud.com/vulnerabilities/64864https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLoghttps://trac.torproject.org/projects/tor/ticket/2352
2011-01-19
Published