CVE-2009-0938: Medium severity Tor (The Onion Router) vulnerability
Published Mar 18, 2009
·Updated
Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service (exit node crash) via "malformed input."
Affected Software
30 affected components
Tor (The Onion Router)<=0.2.0.33
Tor (The Onion Router)=0.2.0.1-alpha
Tor (The Onion Router)=0.2.0.2-alpha
Tor (The Onion Router)=0.2.0.3-alpha
Tor (The Onion Router)=0.2.0.4-alpha
Tor (The Onion Router)=0.2.0.5-alpha
Tor (The Onion Router)=0.2.0.6-alpha
Tor (The Onion Router)=0.2.0.10-alpha
Tor (The Onion Router)=0.2.0.11-alpha
Tor (The Onion Router)=0.2.0.12-alpha
Tor (The Onion Router)=0.2.0.13-alpha
Tor (The Onion Router)=0.2.0.14-alpha
Tor (The Onion Router)=0.2.0.15-alpha
Tor (The Onion Router)=0.2.0.16-alpha
Tor (The Onion Router)=0.2.0.17-alpha
Tor (The Onion Router)=0.2.0.18-alpha
Tor (The Onion Router)=0.2.0.19-alpha
Tor (The Onion Router)=0.2.0.20-alpha
Tor (The Onion Router)=0.2.0.21-alpha
Tor (The Onion Router)=0.2.0.22-alpha
Tor (The Onion Router)=0.2.0.23-alpha
Tor (The Onion Router)=0.2.0.24-alpha
Tor (The Onion Router)=0.2.0.25-alpha
Tor (The Onion Router)=0.2.0.26-alpha
Tor (The Onion Router)=0.2.0.27-alpha
Tor (The Onion Router)=0.2.0.28-alpha
Tor (The Onion Router)=0.2.0.29-alpha
Tor (The Onion Router)=0.2.0.30-alpha
Tor (The Onion Router)=0.2.0.31-alpha
Tor (The Onion Router)=0.2.0.32-alpha
Remediation
Patch Available
Event History
Mar 18, 2009
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·02:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0938?
CVE-2009-0938 is categorized as a denial of service vulnerability.
2
How do I fix CVE-2009-0938?
To fix CVE-2009-0938, upgrade to Tor version 0.2.0.34 or later.
3
What versions of Tor are affected by CVE-2009-0938?
CVE-2009-0938 affects all Tor versions prior to 0.2.0.34.
4
What type of attacks can exploit CVE-2009-0938?
CVE-2009-0938 can be exploited by sending malformed input to directory mirrors, causing an exit node crash.
5
Is CVE-2009-0938 specific to any platform?
CVE-2009-0938 affects the Tor software but is not specific to any particular operating system.