CVE-2020-10592Uncontrolled Resource Consumption in TOR

Severity
7.5HIGHNVD
EPSS
2.0%
top 16.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23
Latest updateMay 24

Description

Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDtorproject/tor0.3.50.3.5.10+2
Debiantorproject/tor< 0.4.2.7-1+3
NVDopensuse/leap15.1
NVDopensuse/backportssle-15

🔴Vulnerability Details

3
GHSA
GHSA-7rpw-j92m-2vr2: Tor before 02022-05-24
OSV
CVE-2020-10592: Tor before 02020-03-23
CVEList
CVE-2020-10592: Tor before 02020-03-23

📋Vendor Advisories

1
Debian
CVE-2020-10592: tor - Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows rem...2020

💬Community

2
Bugzilla
CVE-2020-10592 tor: allows remote attackers to cause a Denial of Service because of excess CPU consumption2020-04-29
Bugzilla
CVE-2020-10592 tor: allows remote attackers to cause a Denial of Service because of excess CPU consumption [epel-all]2020-04-29
CVE-2020-10592 — Uncontrolled Resource Consumption | cvebase