CVE-2012-4419: Medium severity torproject Tor vulnerability
The comparetoraddrtoaddrpolicy function in or/policies.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.21-rc, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a zero-valued port field that is not properly handled during policy comparison.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4419?
CVE-2012-4419 is classified as a denial of service vulnerability due to an assertion failure in the Tor daemon.
How do I fix CVE-2012-4419?
To fix CVE-2012-4419, upgrade Tor to version 0.2.2.39 or later, or 0.2.3.21-rc or later.
Which versions of Tor are affected by CVE-2012-4419?
CVE-2012-4419 affects Tor versions before 0.2.2.39 and 0.2.3.x before 0.2.3.21-rc.
What can exploit CVE-2012-4419?
Remote attackers can exploit CVE-2012-4419 by sending specially crafted traffic that includes a zero-valued port field.
What happens if CVE-2012-4419 is exploited?
Exploiting CVE-2012-4419 may cause the Tor daemon to exit unexpectedly, leading to a denial of service.