cbcvebase.

Debian Tor vulnerabilities

89 known vulnerabilities affecting debian/tor.

Total CVEs
89
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH26MEDIUM42LOW17

Vulnerabilities

Page 1 of 5
CVE-2018-0491P3HIGHCVSS 7.5PoCfixed in tor 0.3.2.10-1 (bookworm)2018
CVE-2018-0491 [HIGH] CVE-2018-0491: tor - A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows ... A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list. Scope: local bookworm: resolved (fixed in 0.3.2.10-1) bullseye: resolved (fixed in 0.3.2.10-1) forky: resolved (fixed in 0.3.2.10-1) sid:
debian
CVE-2007-4174P3MEDIUMCVSS 5.8PoCfixed in tor 0.1.2.16-1 (bookworm)2007
CVE-2007-4174 [MEDIUM] CVE-2007-4174: tor - Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict com... Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) inj
debian
CVE-2010-1676P3CRITICALCVSS 10.0fixed in tor 0.2.1.26-6 (bookworm)2010
CVE-2010-1676 [CRITICAL] CVE-2010-1676: tor - Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-al... Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors. Scope: local bookworm: resolved (fixed in 0.2.1.26-6) bullseye: resolved (fixed in 0.2.1.26-6) forky: resolved (fixed in 0.2.1.26-6) sid: resolved (fixed in 0
debian
CVE-2021-34548P3HIGHCVSS 7.5fixed in tor 0.4.5.9-1 (bookworm)2021
CVE-2021-34548 [HIGH] CVE-2021-34548: tor - An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker c... An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream. Scope: local bookworm: resolved (fixed in 0.4.5.9-1) bullseye: resolved (fixed in 0.4.5.9-1) forky: resolved (fixed in 0.4.5.9-1) sid: resolved (fixed in 0.4.5.9-1) trixie: resolved (fixed in 0.4.
debian
CVE-2021-28089P3HIGHCVSS 7.5fixed in tor 0.4.5.7-1 (bookworm)2021
CVE-2021-28089 [HIGH] CVE-2021-28089: tor - Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to ... Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001. Scope: local bookworm: resolved (fixed in 0.4.5.7-1) bullseye: resolved (fixed in 0.4.5.7-1) forky: resolved (fixed in 0.4.5.7-1) sid: resolved (fixed in 0.4.5.7-1) trixie: resolved (fixed in 0.4.5.7-1)
debian
CVE-2017-11565P3HIGHCVSS 7.5v0.2.9.11-12017-07-23
CVE-2017-11565 [HIGH] CVE-2017-11565: debian/tor.init in the Debian tor_0.2.9.11-1~deb9u1 package for Tor was designed to execute aa-exec debian/tor.init in the Debian tor_0.2.9.11-1~deb9u1 package for Tor was designed to execute aa-exec from the standard system pathname if the apparmor package is installed, but implements this incorrectly (with a wrong assumption that the specific pathname would remain the same forever), which allows attackers to bypass intended AppArmor restrictions by leverag
nvddebian
CVE-2011-2778P3HIGHCVSS 7.6fixed in tor 0.2.2.35-1 (bookworm)2011
CVE-2011-2778 [HIGH] CVE-2011-2778: tor - Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attacke... Multiple heap-based buffer overflows in Tor before 0.2.2.35 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by (1) establishing a SOCKS connection to SocksPort or (2) leveraging a SOCKS proxy configuration. Scope: local bookworm: resolved (fixed in 0.2.2.35-1) bullseye: resolved (fixed in 0.2.2.35-1) forky: resolv
debian
CVE-2017-8823P3HIGHCVSS 8.1fixed in tor 0.3.1.9-1 (bookworm)2017
CVE-2017-8823 [HIGH] CVE-2017-8823: tor - In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.... In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 during intro-point expiration because the expiring list is mismanaged in certain error cases, aka TROVE-2017-013. Scope: local bookworm: resolved (fixed in 0.3.1.9-1) bullseye: resolved (fixed in
debian
CVE-2008-5398P3CRITICALCVSS 9.3fixed in tor 0.2.0.32-1 (bookworm)2008
CVE-2008-5398 [CRITICAL] CVE-2008-5398: tor - Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddress... Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the destination hostname of a refused stream. Scope: local bookworm: resolved (fixed in 0.2.0.
debian
CVE-2015-2689P3HIGHCVSS 7.5fixed in tor 0.2.5.11-1 (bookworm)2015
CVE-2015-2689 [HIGH] CVE-2015-2689: tor - Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending... Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets. Scope: local bookworm: resolved (fixed in 0.2.5.11-1) bullseye: resolved (fixed in 0.2.5.11-1) forky: resolved (fixed
debian
CVE-2016-8860P3HIGHCVSS 7.5fixed in tor 0.2.8.9-1 (bookworm)2016
CVE-2016-8860 [HIGH] CVE-2016-8860: tor - Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that ... Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data had NUL termination, but the implementation of or/buffers.c did not ensure that NUL termination was present, which allows remote attackers to cause a denial of service (client, hidden service, relay, or authority crash) via crafted data. Scope: local boo
debian
CVE-2021-38385P3HIGHCVSS 7.5fixed in tor 0.4.5.10-1 (bookworm)2021
CVE-2021-38385 [HIGH] CVE-2021-38385: tor - Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between b... Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007. Scope: local bookworm: resolved (fixed in 0.4.5.10-1) bullseye: resolved (fixed in 0.4.5.10-1~deb11u1) forky: resolved (fixed in 0.4.5.10-1) sid: resolved (fixed in 0.4.5
debian
CVE-2021-34549P3HIGHCVSS 7.5fixed in tor 0.4.5.9-1 (bookworm)2021
CVE-2021-34549 [HIGH] CVE-2021-34549: tor - An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mi... An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen circuit ID to cause algorithm inefficiency. Scope: local bookworm: resolved (fixed in 0.4.5.9-1) bullseye: resolved (fixed in 0.4.5.9-1) forky: resolved (fixed in 0.4.5.9-1) si
debian
CVE-2021-34550P3HIGHCVSS 7.5fixed in tor 0.4.5.9-1 (bookworm)2021
CVE-2021-34550 [HIGH] CVE-2021-34550: tor - An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion ... An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor Scope: local bookworm: resolved (fixed in 0.4.5.9-1) bullseye: resolved (fixed in 0.4.5.9-1) forky: resolved (fixed in 0.4.5.9-1) sid: resolved (fixed in 0.4.5.9-1) trixi
debian
CVE-2020-15572P3LOWCVSS 7.5fixed in tor 0.4.3.6-1 (bookworm)2020
CVE-2020-15572 [HIGH] CVE-2020-15572: tor - Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denia... Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS), aka TROVE-2020-001. Scope: local bookworm: resolved (fixed in 0.4.3.6-1) bullseye: resolved (fixed in 0.4.3.6-1) forky: resolved (fixed in 0.4.3.6-1) sid: resolved (fixed in 0.4.3.6-1) tri
debian
CVE-2019-8955P3HIGHCVSS 7.5fixed in tor 0.3.5.8-1 (bookworm)2019
CVE-2019-8955 [HIGH] CVE-2019-8955: tor - In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4... In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler. Scope: local bookworm: resolved (fixed in 0.3.5.8-1) bullseye: resolved (fixed in 0.3.5.8-1) forky: resolved (fixed in 0.3.5.8-1) sid: resolved (fixed in
debian
CVE-2020-10592P3HIGHCVSS 7.5fixed in tor 0.4.2.7-1 (bookworm)2020
CVE-2020-10592 [HIGH] CVE-2020-10592: tor - Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows rem... Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002. Scope: local bookworm: resolved (fixed in 0.4.2.7-1) bullseye: resolved (fixed in 0.4.2.7-1) forky: resolved (fixed in 0.4.2.7-1) sid: resolved (fixed in 0.4.2.7-1) trixie: resolved (fixed in 0.4.2.7-1)
debian
CVE-2015-2688P3HIGHCVSS 7.5fixed in tor 0.2.5.11-1 (bookworm)2015
CVE-2015-2688 [HIGH] CVE-2015-2688: tor - buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly ... buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets. Scope: local bookworm: resolved (fixed in 0.2.5.11-1) bullseye: resolved (fixed in 0.2.5.11-1) forky: resolved (f
debian
CVE-2017-8821P3HIGHCVSS 7.5fixed in tor 0.3.1.9-1 (bookworm)2017
CVE-2017-8821 [HIGH] CVE-2017-8821: tor - In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.... In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can cause a denial of service (application hang) via crafted PEM input that signifies a public key requiring a password, which triggers an attempt by the OpenSSL library to ask the user for the password, aka TROVE-2017-011. Scope
debian
CVE-2009-0414P4CRITICALCVSS 10.0fixed in tor 0.2.0.33-1 (bookworm)2009
CVE-2009-0414 [CRITICAL] CVE-2009-0414: tor - Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remo... Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption. Scope: local bookworm: resolved (fixed in 0.2.0.33-1) bullseye: resolved (fixed in 0.2.0.33-1) forky: resolved (fixed in 0.2.0.33-1) sid: resolved (fixed in 0.2.0.33-1) trixie: resolved (fixed in 0.2.0.33-1)
debian
Debian Tor vulnerabilities | cvebase