CVE-2012-3517
published 2012-08-26CVE-2012-3517: Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors related to…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.77%
84.7th percentile
Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors related to failed DNS requests.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.2.3.20-rc-1 (bookworm) | tor 0.2.3.20-rc-1 (bookworm) |
| tor | tor | <= 0.2.2.37 | — |
| torproject | tor | >= 0 < 0.2.3.20-rc-1 | 0.2.3.20-rc-1 |
| torproject | tor | >= 0 < 0.2.3.20-rc-1 | 0.2.3.20-rc-1 |
| torproject | tor | >= 0 < 0.2.3.20-rc-1 | 0.2.3.20-rc-1 |
| torproject | tor | >= 0 < 0.2.3.20-rc-1 | 0.2.3.20-rc-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
vendor_redhat·2012-01-18·CVSS 4.3
CVE-2012-0079 [MEDIUM] OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
Unspecified vulnerability in Oracle OpenSSO 7.1 and 8.0 allows remote attackers to affect integrity via unknown vectors related to Administration.
Statement: Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso quickstart has been removed in JBoss Enterprise SOA Platform 5.3.0 to address these flaws. Users interested in continuing to
Debian
CVE-2012-3517: tor - Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote ...
vendor_debian·2012·CVSS 5.0
CVE-2012-3517 [MEDIUM] CVE-2012-3517: tor - Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote ...
Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors related to failed DNS requests.
Scope: local
bookworm: resolved (fixed in 0.2.3.20-rc-1)
bullseye: resolved (fixed in 0.2.3.20-rc-1)
forky: resolved (fixed in 0.2.3.20-rc-1)
sid: resolved (fixed in 0.2.3.20-rc-1)
trixie: resolved (fixed in 0.2.3.20-rc-1)
Red Hat
OpenSSO: unspecified vulnerability in the authentication component
vendor_redhat·2011-10-18·CVSS 4.3
CVE-2011-3517 [MEDIUM] OpenSSO: unspecified vulnerability in the authentication component
OpenSSO: unspecified vulnerability in the authentication component
Unspecified vulnerability in the Oracle OpenSSO component in Oracle Sun Products Suite 8.0 allows remote attackers to affect availability via unknown vectors related to Authentication.
Statement: Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso quickstart has been removed in JBoss Enterprise SOA Platform 5.3.0 to address these flaws. Users interested in continui
Red Hat
OpenSSO: unspecified vulnerability in the authentication component
vendor_redhat·2011-10-18·CVSS 4.3
CVE-2011-3506 [MEDIUM] OpenSSO: unspecified vulnerability in the authentication component
OpenSSO: unspecified vulnerability in the authentication component
Unspecified vulnerability in the Oracle OpenSSO component in Oracle Sun Products Suite 7.1 and 8.0 allows remote attackers to affect integrity via unknown vectors related to Authentication.
Statement: Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso quickstart has been removed in JBoss Enterprise SOA Platform 5.3.0 to address these flaws. Users interested in con
GHSA
GHSA-pww9-9prw-24pv: Use-after-free vulnerability in dns
ghsa_unreviewed·2022-05-17
CVE-2012-3517 [MEDIUM] GHSA-pww9-9prw-24pv: Use-after-free vulnerability in dns
Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors related to failed DNS requests.
OSV
CVE-2012-3517: Use-after-free vulnerability in dns
osv·2012-08-26·CVSS 5.0
CVE-2012-3517 [MEDIUM] CVE-2012-3517: Use-after-free vulnerability in dns
Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors related to failed DNS requests.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3517 tor: Read from freed memory and double free by processing failed DNS request
bugzilla·2012-08-21·CVSS 5.0
CVE-2012-3517 [MEDIUM] CVE-2012-3517 tor: Read from freed memory and double free by processing failed DNS request
CVE-2012-3517 tor: Read from freed memory and double free by processing failed DNS request
A read from already freed memory and double free flaws were found in the way Tor, a connection-based low-latency anonymous communication system, performed processing of certain failing DNS requests. A remote attacker could issue a specially-crafted DNS request that, when processed would lead to tor executable crash.
Upstream ticket:
[1] https://trac.torproject.org/projects/tor/ticket/6480
Relevant patch:
[2] https://gitweb.torproject.org/tor.git/commitdiff/62637fa22405278758febb1743da9af562524d4c
References:
[3] https://lists.torproject.org/pipermail/tor-announce/2012-August/000086.html
[4] https://bugzilla.novell.com/show_bug.cgi?id=776642
Discussion:
This issue affects the version of the tor
Bugzilla
CVE-2012-0079 OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
bugzilla·2012-01-23·CVSS 4.3
CVE-2012-0079 [MEDIUM] CVE-2012-0079 OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
CVE-2012-0079 OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-0079 to the following vulnerability:
Unspecified vulnerability in Oracle OpenSSO 7.1 and 8.0 allows remote attackers to affect integrity via unknown vectors related to Administration.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0079
Discussion:
Statement:
Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application i
Bugzilla
CVE-2011-3517 Oracle OpenSSO: unspecified vulnerability in the authentication component
bugzilla·2011-10-26·CVSS 4.3
CVE-2011-3517 [MEDIUM] CVE-2011-3517 Oracle OpenSSO: unspecified vulnerability in the authentication component
CVE-2011-3517 Oracle OpenSSO: unspecified vulnerability in the authentication component
Oracle OpenSSO 8.0 exposes an unspecified vulnerability in the authentication component, allowing a remote attacker to perform a denial of service (CVE-2011-3517).
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html
---
Statement:
Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso qui
Bugzilla
CVE-2011-3506 Oracle OpenSSO: unspecified vulnerability in the authentication component
bugzilla·2011-10-26·CVSS 4.3
CVE-2011-3506 [MEDIUM] CVE-2011-3506 Oracle OpenSSO: unspecified vulnerability in the authentication component
CVE-2011-3506 Oracle OpenSSO: unspecified vulnerability in the authentication component
Oracle OpenSSO 7.1 and 8.0 expose an unspecified vulnerability in the authentication component, allowing attackers to manipulate certain data (CVE-2011-3506).
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html
---
Statement:
Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso quicksta
http://lists.fedoraproject.org/pipermail/package-announce/2012-September/088006.htmlhttp://lists.opensuse.org/opensuse-updates/2012-08/msg00048.htmlhttp://openwall.com/lists/oss-security/2012/08/21/6http://security.gentoo.org/glsa/glsa-201301-03.xmlhttps://bugzilla.redhat.com/show_bug.cgi?id=849949https://gitweb.torproject.org/tor.git/commit/62637fa22405278758febb1743da9af562524d4chttps://lists.torproject.org/pipermail/tor-announce/2012-August/000086.htmlhttps://trac.torproject.org/projects/tor/ticket/6480http://lists.fedoraproject.org/pipermail/package-announce/2012-September/088006.htmlhttp://lists.opensuse.org/opensuse-updates/2012-08/msg00048.htmlhttp://openwall.com/lists/oss-security/2012/08/21/6http://security.gentoo.org/glsa/glsa-201301-03.xmlhttps://bugzilla.redhat.com/show_bug.cgi?id=849949https://gitweb.torproject.org/tor.git/commit/62637fa22405278758febb1743da9af562524d4chttps://lists.torproject.org/pipermail/tor-announce/2012-August/000086.htmlhttps://trac.torproject.org/projects/tor/ticket/6480
2012-08-26
Published