CVE-2017-0376
published 2017-06-09CVE-2017-0376: The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell…
PriorityP433high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
2.18%
80.3th percentile
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tor | < tor 0.2.9.11-1 (bookworm) | tor 0.2.9.11-1 (bookworm) |
| torproject | tor | < 0.3.0.8 | 0.3.0.8 |
| torproject | tor | >= 0 < 0.2.9.11-1 | 0.2.9.11-1 |
| torproject | tor | >= 0 < 0.2.9.11-1 | 0.2.9.11-1 |
| torproject | tor | >= 0 < 0.2.9.11-1 | 0.2.9.11-1 |
| torproject | tor | >= 0 < 0.2.9.11-1 | 0.2.9.11-1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-0376: tor - The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (ass...
vendor_debian·2017·CVSS 7.5
CVE-2017-0376 [HIGH] CVE-2017-0376: tor - The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (ass...
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit.
Scope: local
bookworm: resolved (fixed in 0.2.9.11-1)
bullseye: resolved (fixed in 0.2.9.11-1)
forky: resolved (fixed in 0.2.9.11-1)
sid: resolved (fixed in 0.2.9.11-1)
trixie: resolved (fixed in 0.2.9.11-1)
GHSA
GHSA-4cxm-8xrj-7c53: The hidden-service feature in Tor before 0
ghsa_unreviewed·2022-05-13
CVE-2017-0376 [HIGH] CWE-617 GHSA-4cxm-8xrj-7c53: The hidden-service feature in Tor before 0
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit.
OSV
CVE-2017-0376: The hidden-service feature in Tor before 0
osv·2017-06-09·CVSS 7.5
CVE-2017-0376 [HIGH] CVE-2017-0376: The hidden-service feature in Tor before 0
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [fedora-all]
bugzilla·2017-06-14·CVSS 7.5
CVE-2017-0375 [HIGH] CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [fedora-all]
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [epel-all]
bugzilla·2017-06-14·CVSS 7.5
CVE-2017-0375 [HIGH] CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [epel-all]
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
Bugzilla
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities
bugzilla·2017-06-13·CVSS 7.5
CVE-2017-0375 [HIGH] CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities
CVE-2017-0375 CVE-2017-0376 tor: Multiple vulnerabilities
CVE-2017-0375
The hidden-service feature in Tor before 0.3.0.8 allows a denial of
service (assertion failure and daemon exit) in the
relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.
https://trac.torproject.org/projects/tor/ticket/22493
https://github.com/torproject/tor/commit/79b59a2dfcb68897ee89d98587d09e55f07e68d7
CVE-2017-0376
The hidden-service feature in Tor before 0.3.0.8 allows a denial of
service (assertion failure and daemon exit) in the
connection_edge_process_relay_cell function via a BEGIN_DIR cell on a
rendezvous circuit.
https://trac.torproject.org/projects/tor/ticket/22494
https://github.com/torproject/tor/commit/56a7c5bc15e0447203a491c1ee37de9939ad1dcd
References:
https://lists.torproject.o
http://www.debian.org/security/2017/dsa-3877https://github.com/torproject/tor/commit/56a7c5bc15e0447203a491c1ee37de9939ad1dcdhttps://lists.torproject.org/pipermail/tor-announce/2017-June/000131.htmlhttps://trac.torproject.org/projects/tor/ticket/22494http://www.debian.org/security/2017/dsa-3877https://github.com/torproject/tor/commit/56a7c5bc15e0447203a491c1ee37de9939ad1dcdhttps://lists.torproject.org/pipermail/tor-announce/2017-June/000131.htmlhttps://trac.torproject.org/projects/tor/ticket/22494
2017-06-09
Published