CVE-2011-1924
published 2011-06-14CVE-2011-1924: Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.82%
85.0th percentile
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory authority crash) via a crafted policy that triggers creation of a long port list.
Affected
209 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.2.1.30-1 (bookworm) | tor 0.2.1.30-1 (bookworm) |
| tor | tor | <= 0.2.1.29 | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f3pm-2c82-x85g: Buffer overflow in the policy_summarize function in or/policies
ghsa_unreviewed·2022-05-17
CVE-2011-1924 [MEDIUM] CWE-119 GHSA-f3pm-2c82-x85g: Buffer overflow in the policy_summarize function in or/policies
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory authority crash) via a crafted policy that triggers creation of a long port list.
OSV
CVE-2011-1924: Buffer overflow in the policy_summarize function in or/policies
osv·2011-06-14·CVSS 5.0
CVE-2011-1924 [MEDIUM] CVE-2011-1924: Buffer overflow in the policy_summarize function in or/policies
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory authority crash) via a crafted policy that triggers creation of a long port list.
Debian
CVE-2011-1924: tor - Buffer overflow in the policy_summarize function in or/policies.c in Tor before ...
vendor_debian·2011·CVSS 5.0
CVE-2011-1924 [MEDIUM] CVE-2011-1924: tor - Buffer overflow in the policy_summarize function in or/policies.c in Tor before ...
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory authority crash) via a crafted policy that triggers creation of a long port list.
Scope: local
bookworm: resolved (fixed in 0.2.1.30-1)
bullseye: resolved (fixed in 0.2.1.30-1)
forky: resolved (fixed in 0.2.1.30-1)
sid: resolved (fixed in 0.2.1.30-1)
trixie: resolved (fixed in 0.2.1.30-1)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061258.htmlhttp://secunia.com/advisories/43548http://secunia.com/advisories/44862http://www.securityfocus.com/bid/46618https://bugzilla.redhat.com/show_bug.cgi?id=705192https://bugzilla.redhat.com/show_bug.cgi?id=705194https://gitweb.torproject.org/tor.git/commit/43414eb98821d3b5c6c65181d7545ce938f82c8ehttps://lists.torproject.org/pipermail/tor-announce/2011-February/000000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/061258.htmlhttp://secunia.com/advisories/43548http://secunia.com/advisories/44862http://www.securityfocus.com/bid/46618https://bugzilla.redhat.com/show_bug.cgi?id=705192https://bugzilla.redhat.com/show_bug.cgi?id=705194https://gitweb.torproject.org/tor.git/commit/43414eb98821d3b5c6c65181d7545ce938f82c8ehttps://lists.torproject.org/pipermail/tor-announce/2011-February/000000.html
2011-06-14
Published