cbcvebase.

Debian Tor vulnerabilities

89 known vulnerabilities affecting debian/tor.

Total CVEs
89
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH26MEDIUM42LOW17

Vulnerabilities

Page 2 of 5
CVE-2016-1254P3HIGHCVSS 7.5fixed in tor 0.2.9.8-2 (bookworm)2016
CVE-2016-1254 [HIGH] CVE-2016-1254: tor - Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (c... Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor. Scope: local bookworm: resolved (fixed in 0.2.9.8-2) bullseye: resolved (fixed in 0.2.9.8-2) forky: resolved (fixed in 0.2.9.8-2) sid: resolved (fixed in 0.2.9.8-2) trixie: resolved (fixed in 0.2.9.8-2)
debian
CVE-2020-10593P3HIGHCVSS 7.5fixed in tor 0.4.2.7-1 (bookworm)2020
CVE-2020-10593 [HIGH] CVE-2020-10593: tor - Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows rem... Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negotiated twice on the same circuit. Scope: local bookworm: resolved (fixed in 0.4.2.7-1) bullseye: resolved (fixed in 0.4.2.7-
debian
CVE-2017-8819P3HIGHCVSS 7.5fixed in tor 0.3.1.9-1 (bookworm)2017
CVE-2017-8819 [HIGH] CVE-2017-8819: tor - In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.... In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion services, aka TROVE-2017-009. An attacker can send many INTRODUCE2 cells to trigger this issue. Scope: local bookworm: resolved (fixed in 0.3.1.9-1) bullseye: resolved (fixed
debian
CVE-2006-3409P3HIGHCVSS 7.5fixed in tor 0.1.1.20-1 (bookworm)2006
CVE-2006-3409 [HIGH] CVE-2006-3409: tor - Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbit... Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer overflow when elements are added to smartlists. Scope: local bookworm: resolved (fixed in 0.1.1.20-1) bullseye: resolved (fixed in 0.1.1.20-1) forky: resolved (fixed in 0.1.1.20-1) sid: resolved (fixed in 0.1.1.20-1) trixie: resolved
debian
CVE-2018-0490P4HIGHCVSS 7.5fixed in tor 0.3.2.10-1 (bookworm)2018
CVE-2018-0490 [HIGH] CVE-2018-0490: tor - An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3... An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service (NULL pointer dereference and directory-authority crash) via a misformatted relay descriptor that is mishandled during voting. Scope: local bookworm: reso
debian
CVE-2015-2928P4HIGHCVSS 7.5fixed in tor 0.2.5.12-1 (bookworm)2015
CVE-2015-2928 [HIGH] CVE-2015-2928: tor - The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x be... The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors. Scope: local bookworm: resolved (fixed in 0.2.5.12-1) bullseye: resolved (fixed in 0.2.5.12-1) forky: resolved (fixed in 0.2.5.12-1) sid:
debian
CVE-2011-0427P4MEDIUMCVSS 6.8fixed in tor 0.2.1.29-1 (bookworm)2011
CVE-2011-0427 [MEDIUM] CVE-2011-0427: tor - Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-al... Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. Scope: local bookworm: resolved (fixed in 0.2.1.29-1) bullseye: resolved (fixed in 0.2.1.29-1) forky: resolved (fixed in 0.2.1.29-1)
debian
CVE-2017-0376P4HIGHCVSS 7.5fixed in tor 0.2.9.11-1 (bookworm)2017
CVE-2017-0376 [HIGH] CVE-2017-0376: tor - The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (ass... The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit. Scope: local bookworm: resolved (fixed in 0.2.9.11-1) bullseye: resolved (fixed in 0.2.9.11-1) forky: resolved (fixed in 0.2.9.11-1) sid: resolved (fixed in 0.2.9.11
debian
CVE-2017-8820P4HIGHCVSS 7.5fixed in tor 0.3.1.9-1 (bookworm)2017
CVE-2017-8820 [HIGH] CVE-2017-8820: tor - In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.... In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory authorities via a malformed descriptor, aka TROVE-2017-010. Scope: local bookworm: resolved (fixed in 0.3.1.9-1) bullseye: reso
debian
CVE-2022-33903P4HIGHCVSS 7.5fixed in tor 0.4.7.8-1 (bookworm)2022
CVE-2022-33903 [HIGH] CVE-2022-33903: tor - Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT est... Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation. Scope: local bookworm: resolved (fixed in 0.4.7.8-1) bullseye: resolved forky: resolved (fixed in 0.4.7.8-1) sid: resolved (fixed in 0.4.7.8-1) trixie: resolved (fixed in 0.4.7.8-1)
debian
CVE-2006-3412P4MEDIUMCVSS 6.4fixed in tor 0.1.1.20-1 (bookworm)2006
CVE-2006-3412 [MEDIUM] CVE-2006-3412: tor - Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which a... Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restrictions for dirservers, direct connections, or proxy servers. Scope: local bookworm: resolved (fixed in 0.1.1.20-1) bullseye: resolved (fixed in 0.1.1.20-1) forky: resolved (fixed in 0.1.1.20-1) sid: resolved (fixed in 0.1.1.20-1) trixie:
debian
CVE-2015-2929P4HIGHCVSS 7.5fixed in tor 0.2.5.12-1 (bookworm)2015
CVE-2015-2929 [HIGH] CVE-2015-2929: tor - The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x be... The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed HS descriptor. Scope: local bookworm: resolved (fixed in 0.2.5.12-1) bullseye: resolved (fixed in 0.2.5.12-1) forky: resolved (fixed in 0.2.5.12
debian
CVE-2009-0939P4CRITICALCVSS 10.0fixed in tor 0.2.0.34-1 (bookworm)2009
CVE-2009-0939 [CRITICAL] CVE-2009-0939: tor - Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown... Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0. Scope: local bookworm: resolved (fixed in 0.2.0.34-1) bullseye: resolved (fixed in 0.2.0.34-1) forky: resolved (fixed in 0.2.0.34-1) sid: resolved (fixed in 0.2.0.34-1) trixie: resolved (fixed in 0.2
debian
CVE-2021-28090P4MEDIUMCVSS 5.3fixed in tor 0.4.5.7-1 (bookworm)2021
CVE-2021-28090 [MEDIUM] CVE-2021-28090: tor - Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities t... Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002. Scope: local bookworm: resolved (fixed in 0.4.5.7-1) bullseye: resolved (fixed in 0.4.5.7-1) forky: resolved (fixed in 0.4.5.7-1) sid: resolved (fixed in 0.4.5.7-1) trixie: resolved (fixed in 0.4.5.7-1)
debian
CVE-2023-23589P4MEDIUMCVSS 6.5fixed in tor 0.4.7.13-1 (bookworm)2023
CVE-2023-23589 [MEDIUM] CVE-2023-23589: tor - The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsaf... The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002. Scope: local bookworm: resolved (fixed in 0.4.7.13-1) bullseye: resolved (fixed in 0.4.5.16-1) forky: resolved (fixed in 0.4.7.13-1) sid: resolved (fixed in 0.4.7.13-1) trixie: resolved (fixed in 0.4.7.13-
debian
CVE-2014-5117P4MEDIUMCVSS 5.8fixed in tor 0.2.4.23-1 (bookworm)2014
CVE-2014-5117 [MEDIUM] CVE-2014-5117: tor - Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an ... Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an inbound RELAY_EARLY cell is received by a client, which makes it easier for remote attackers to conduct traffic-confirmation attacks by using the pattern of RELAY and RELAY_EARLY cells as a means of communicating information about hidden service names. Scope: local bookworm: resolved (fixed
debian
CVE-2017-0380P4MEDIUMCVSS 5.9fixed in tor 0.3.1.7-1 (bookworm)2017
CVE-2017-0380 [MEDIUM] CVE-2017-0380: tor - The rend_service_intro_established function in or/rendservice.c in Tor before 0.... The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attackers to obtain sensitive information by leveraging access to the log files of a hidden service, because uninitialized stack data is in
debian
CVE-2006-3417P4MEDIUMCVSS 6.4fixed in tor 0.1.1.20-1 (bookworm)2006
CVE-2006-3417 [MEDIUM] CVE-2006-3417: tor - Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable fl... Tor client before 0.1.1.20 prefers entry points based on is_fast or is_stable flags, which could allow remote attackers to be preferred over nodes that are identified as more trustworthy "entry guard" (is_guard) systems by directory authorities. Scope: local bookworm: resolved (fixed in 0.1.1.20-1) bullseye: resolved (fixed in 0.1.1.20-1) forky: resolved (fixed in 0.1.1
debian
CVE-2007-4098P4MEDIUMCVSS 5.8fixed in tor 0.1.2.15-1 (bookworm)2007
CVE-2007-4098 [MEDIUM] CVE-2007-4098: tor - Tor before 0.1.2.15 does not properly distinguish "streamids from different exit... Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams. Scope: local bookworm: resolved (fixed in 0.1.2.15-1) bullseye: resolved (fixed in 0.1.2.15-1) forky: resolved (fixed in 0.1.2.15-1) sid: resolved (fixed in 0.1.2.15-1) trixie: resolv
debian
CVE-2008-5397P4HIGHCVSS 7.2fixed in tor 0.2.0.32-1 (bookworm)2008
CVE-2008-5397 [HIGH] CVE-2008-5397: tor - Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configu... Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process. Scope: local bookworm: resolved (fixed in 0.2.0.32-1) bullseye: resolved (fixed in 0.2.0.32-1) forky: resolved (fixed in 0.2.0.32-1) sid: resolved (fixe
debian
Debian Tor vulnerabilities | cvebase