CVE-2012-2249Reachable Assertion in TOR

7 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 35.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 3
Latest updateMay 17

Description

Tor before 0.2.3.23-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a renegotiation attempt that occurs after the initiation of the V3 link protocol.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiantorproject/tor< 0.2.3.23-rc-1+3
NVDtorproject/tor0.2.3.22+81

🔴Vulnerability Details

3
GHSA
GHSA-h977-vhf7-vm3w: Tor before 02022-05-17
CVEList
CVE-2012-2249: Tor before 02014-02-03
OSV
CVE-2012-2249: Tor before 02014-02-03

📋Vendor Advisories

1
Debian
CVE-2012-2249: tor - Tor before 0.2.3.23-rc allows remote attackers to cause a denial of service (ass...2012

💬Community

2
Bugzilla
CVE-2012-2249 tor: denial of service via a renegotiation attempt [epel-5]2014-02-03
Bugzilla
CVE-2012-2249 tor: denial of service via a renegotiation attempt2014-02-03
CVE-2012-2249 — Reachable Assertion in Torproject TOR | cvebase