CVE-2012-4922: Input Validation
The tortimegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed directory object, a different vulnerability than CVE-2012-4419.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4922?
CVE-2012-4922 has been classified as a denial of service vulnerability due to its potential to crash the Tor daemon.
How do I fix CVE-2012-4922?
To fix CVE-2012-4922, upgrade to Tor version 0.2.3.22-rc or later, which contains the necessary patch.
What versions are affected by CVE-2012-4922?
CVE-2012-4922 affects Tor versions before 0.2.2.39 and all 0.2.3.x versions prior to 0.2.3.22-rc.
Can CVE-2012-4922 be exploited remotely?
Yes, CVE-2012-4922 can be exploited remotely through a malformed directory object.
Is there a workaround for CVE-2012-4922 if I cannot update?
There is no documented workaround for CVE-2012-4922, so updating is the recommended solution.