CVE-2009-2425: Input Validation
Published Jul 10, 2009
·Updated
Tor before 0.2.0.35 allows remote attackers to cause a denial of service (application crash) via a malformed router descriptor.
Affected Software
1 affected component
Tor (The Onion Router)=0.2.0.35
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jul 10, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2425?
CVE-2009-2425 is classified as a denial of service vulnerability.
2
How do I fix CVE-2009-2425?
To mitigate CVE-2009-2425, upgrade Tor to version 0.2.0.35 or later.
3
What type of vulnerability is CVE-2009-2425?
CVE-2009-2425 is a denial of service vulnerability that allows application crashes.
4
Who is affected by CVE-2009-2425?
CVE-2009-2425 affects users running versions of Tor prior to 0.2.0.35.
5
Can CVE-2009-2425 be exploited remotely?
Yes, CVE-2009-2425 can be exploited by remote attackers through a malformed router descriptor.