CVE-2020-10593Missing Release of Memory after Effective Lifetime in TOR

Severity
7.5HIGHNVD
EPSS
1.2%
top 20.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23
Latest updateMay 24

Description

Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negotiated twice on the same circuit.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDtorproject/tor0.3.50.3.5.10+2
Debiantorproject/tor< 0.4.2.7-1+3
NVDopensuse/leap15.1

🔴Vulnerability Details

3
GHSA
GHSA-v9h5-mm27-9j99: Tor before 02022-05-24
CVEList
CVE-2020-10593: Tor before 02020-03-23
OSV
CVE-2020-10593: Tor before 02020-03-23

📋Vendor Advisories

1
Debian
CVE-2020-10593: tor - Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows rem...2020

💬Community

2
Bugzilla
CVE-2020-10593 tor: there's a memory leak allowing remote attackers to cause a DoS2020-04-29
Bugzilla
CVE-2020-10593 tor: there's a memory leak allowing remote attackers to cause a DoS [epel-all]2020-04-29
CVE-2020-10593 — Torproject TOR vulnerability | cvebase