cbcvebase.
CVE-2017-8820
published 2017-12-03

CVE-2017-8820: In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause…

high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory authorities via a malformed descriptor, aka TROVE-2017-010.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiantor< tor 0.3.1.9-1 (bookworm)tor 0.3.1.9-1 (bookworm)
tor_projecttor< 0.2.5.160.2.5.16
tor_projecttor>= 0.2.6 < 0.2.8.170.2.8.17
tor_projecttor>= 0.2.9 < 0.2.9.140.2.9.14
tor_projecttor>= 0.3.0 < 0.3.0.130.3.0.13
tor_projecttor>= 0.3.1 < 0.3.1.90.3.1.9
torprojecttor>= 0 < 0.3.1.9-10.3.1.9-1
torprojecttor>= 0 < 0.3.1.9-10.3.1.9-1
torprojecttor>= 0 < 0.3.1.9-10.3.1.9-1
torprojecttor>= 0 < 0.3.1.9-10.3.1.9-1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH