CVE-2017-0376Reachable Assertion in TOR

CWE-617Reachable Assertion10 documents7 sources
Severity
7.5HIGHNVD
EPSS
0.8%
top 25.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 9
Latest updateMay 13

Description

The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDtorproject/tor< 0.3.0.8
Debiantorproject/tor< 0.2.9.11-1+3

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4cxm-8xrj-7c53: The hidden-service feature in Tor before 02022-05-13
OSV
CVE-2017-0376: The hidden-service feature in Tor before 02017-06-09
CVEList
CVE-2017-0376: The hidden-service feature in Tor before 02017-06-09

📋Vendor Advisories

1
Debian
CVE-2017-0376: tor - The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (ass...2017

💬Community

3
Bugzilla
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [fedora-all]2017-06-14
Bugzilla
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [epel-all]2017-06-14
Bugzilla
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities2017-06-13
CVE-2017-0376 — Reachable Assertion in Torproject TOR | cvebase