CVE-2009-0936: Medium severity Tor (The Onion Router) vulnerability
Published Mar 18, 2009
·Updated
Unspecified vulnerability in Tor before 0.2.0.34 allows attackers to cause a denial of service (infinite loop) via "corrupt votes."
Affected Software
30 affected components
Tor (The Onion Router)=0.2.0.11-alpha
Tor (The Onion Router)=0.2.0.22-alpha
Tor (The Onion Router)=0.2.0.19-alpha
Tor (The Onion Router)=0.2.0.31-alpha
Tor (The Onion Router)=0.2.0.14-alpha
Tor (The Onion Router)=0.2.0.28-alpha
Tor (The Onion Router)=0.2.0.17-alpha
Tor (The Onion Router)=0.2.0.25-alpha
Tor (The Onion Router)=0.2.0.26-alpha
Tor (The Onion Router)=0.2.0.12-alpha
Tor (The Onion Router)=0.2.0.3-alpha
Tor (The Onion Router)=0.2.0.18-alpha
Tor (The Onion Router)=0.2.0.4-alpha
Tor (The Onion Router)=0.2.0.27-alpha
Tor (The Onion Router)=0.2.0.32-alpha
Tor (The Onion Router)=0.2.0.15-alpha
Tor (The Onion Router)=0.2.0.2-alpha
Tor (The Onion Router)=0.2.0.24-alpha
Tor (The Onion Router)=0.2.0.21-alpha
Tor (The Onion Router)=0.2.0.20-alpha
Tor (The Onion Router)=0.2.0.13-alpha
Tor (The Onion Router)=0.2.0.1-alpha
Tor (The Onion Router)=0.2.0.23-alpha
Tor (The Onion Router)=0.2.0.10-alpha
Tor (The Onion Router)<=0.2.0.33
Tor (The Onion Router)=0.2.0.29-alpha
Tor (The Onion Router)=0.2.0.30-alpha
Tor (The Onion Router)=0.2.0.6-alpha
Tor (The Onion Router)=0.2.0.16-alpha
Tor (The Onion Router)=0.2.0.5-alpha
Remediation
Patch Available
Event History
Mar 18, 2009
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·02:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0936?
CVE-2009-0936 has a severity rating that indicates a potential denial of service due to corrupt votes.
2
What versions of Tor are affected by CVE-2009-0936?
CVE-2009-0936 affects multiple alpha versions of Tor, specifically all versions prior to 0.2.0.34.
3
How do I fix CVE-2009-0936?
To mitigate CVE-2009-0936, upgrade to Tor version 0.2.0.34 or later.
4
What type of attack does CVE-2009-0936 allow?
CVE-2009-0936 allows attackers to execute a denial of service attack by causing an infinite loop via corrupt votes.
5
Is there a workaround for CVE-2009-0936?
There is no specific workaround available for CVE-2009-0936 other than updating to a patched version of Tor.