CVE-2017-0375
published 2017-06-09CVE-2017-0375: The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function…
PriorityP433high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.61%
83.7th percentile
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | — | — |
| torproject | tor | < 0.3.0.8 | 0.3.0.8 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2mmr-2hq6-5c3v: The hidden-service feature in Tor before 0
ghsa_unreviewed·2022-05-13
CVE-2017-0375 [HIGH] CWE-617 GHSA-2mmr-2hq6-5c3v: The hidden-service feature in Tor before 0
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.
Debian
CVE-2017-0375: tor - The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (ass...
vendor_debian·2017·CVSS 7.5
CVE-2017-0375 [HIGH] CVE-2017-0375: tor - The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (ass...
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [fedora-all]
bugzilla·2017-06-14·CVSS 7.5
CVE-2017-0375 [HIGH] CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [fedora-all]
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [epel-all]
bugzilla·2017-06-14·CVSS 7.5
CVE-2017-0375 [HIGH] CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [epel-all]
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
Bugzilla
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities
bugzilla·2017-06-13·CVSS 7.5
CVE-2017-0375 [HIGH] CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities
CVE-2017-0375
The hidden-service feature in Tor before 0.3.0.8 allows a denial of
service (assertion failure and daemon exit) in the
relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.
https://trac.torproject.org/projects/tor/ticket/22493
https://github.com/torproject/tor/commit/79b59a2dfcb68897ee89d98587d09e55f07e68d7
CVE-2017-0376
The hidden-service feature in Tor before 0.3.0.8 allows a denial of
service (assertion failure and daemon exit) in the
connection_edge_process_relay_cell function via a BEGIN_DIR cell on a
rendezvous circuit.
https://trac.torproject.org/projects/tor/ticket/22494
https://github.com/torproject/tor/commit/56a7c5bc15e0447203a491c1ee37de9939ad1dcd
References:
https://lists.torproject.o
http://www.securityfocus.com/bid/99017https://github.com/torproject/tor/commit/79b59a2dfcb68897ee89d98587d09e55f07e68d7https://lists.torproject.org/pipermail/tor-announce/2017-June/000131.htmlhttps://trac.torproject.org/projects/tor/ticket/22493http://www.securityfocus.com/bid/99017https://github.com/torproject/tor/commit/79b59a2dfcb68897ee89d98587d09e55f07e68d7https://lists.torproject.org/pipermail/tor-announce/2017-June/000131.htmlhttps://trac.torproject.org/projects/tor/ticket/22493
2017-06-09
Published