CVE-2022-33903
published 2022-07-17CVE-2022-33903: Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
PriorityP432high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.23%
65.4th percentile
Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.4.7.8-1 (bookworm) | tor 0.4.7.8-1 (bookworm) |
| torproject | tor | >= 0 < 0.4.7.8-1 | 0.4.7.8-1 |
| torproject | tor | >= 0 < 0.4.7.8-1 | 0.4.7.8-1 |
| torproject | tor | >= 0 < 0.4.7.8-1 | 0.4.7.8-1 |
| torproject | tor | >= 0.4.7.1 < 0.4.7.8 | 0.4.7.8 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-33903: tor - Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT est...
vendor_debian·2022·CVSS 7.5
CVE-2022-33903 [HIGH] CVE-2022-33903: tor - Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT est...
Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
Scope: local
bookworm: resolved (fixed in 0.4.7.8-1)
bullseye: resolved
forky: resolved (fixed in 0.4.7.8-1)
sid: resolved (fixed in 0.4.7.8-1)
trixie: resolved (fixed in 0.4.7.8-1)
VulDB
Tor Browser up to 0.4.7.7 RTT Estimation denial of service (EUVD-2022-36940)
vuldb·2026-06-12·CVSS 7.5
CVE-2022-33903 [HIGH] Tor Browser up to 0.4.7.7 RTT Estimation denial of service (EUVD-2022-36940)
A vulnerability classified as problematic was found in Tor Browser up to 0.4.7.7. The affected element is an unknown function of the component RTT Estimation Handler. The manipulation results in denial of service.
This vulnerability was named CVE-2022-33903. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.
GHSA
GHSA-g7xf-5c64-42cx: Tor 0
ghsa_unreviewed·2022-07-18
CVE-2022-33903 [HIGH] GHSA-g7xf-5c64-42cx: Tor 0
Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
OSV
CVE-2022-33903: Tor 0
osv·2022-07-17·CVSS 7.5
CVE-2022-33903 [HIGH] CVE-2022-33903: Tor 0
Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.torproject.org/pipermail/tor-announce/2022-June/000242.htmlhttps://security-tracker.debian.org/tracker/CVE-2022-33903https://security.gentoo.org/glsa/202305-11https://lists.torproject.org/pipermail/tor-announce/2022-June/000242.htmlhttps://security-tracker.debian.org/tracker/CVE-2022-33903https://security.gentoo.org/glsa/202305-11
2022-07-17
Published