CVE-2015-2928: High severity tor project tor vulnerability
The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-2928?
CVE-2015-2928 is a vulnerability in the Hidden Service (HS) server implementation in Tor before version 0.2.4.27, 0.2.5.x before version 0.2.5.12, and 0.2.6.x before version 0.2.6.7.
What is the severity of CVE-2015-2928?
CVE-2015-2928 has a severity rating of 7.5 (high).
How does CVE-2015-2928 affect Tor?
CVE-2015-2928 allows remote attackers to cause a denial of service (assertion failure and daemon exit) in Tor.
What software versions are affected by CVE-2015-2928?
CVE-2015-2928 affects Tor versions before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7.
Is there a fix available for CVE-2015-2928?
Yes, updating to Tor version 0.2.4.27, 0.2.5.12, or 0.2.6.7 will fix the vulnerability.