CVE-2015-2929: High severity tor project tor vulnerability
Published Jan 24, 2020
·Updated
The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed HS descriptor.
Affected Software
3 affected components
torproject Tor<0.2.4.27
torproject Tor>=0.2.5.1<0.2.5.12
torproject Tor>=0.2.6.1<0.2.6.7
Event History
Jan 24, 2020
CVE Published
via MITRE·05:22 PM
Data Sourced
via MITRE·05:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2015-2929.
2
What is the severity of CVE-2015-2929?
The severity of CVE-2015-2929 is high with a CVSS score of 7.5.
3
What software is affected by CVE-2015-2929?
The Tor software versions before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 are affected by CVE-2015-2929.
4
How can CVE-2015-2929 be exploited?
CVE-2015-2929 can be exploited by remote servers to cause a denial of service by sending a malformed HS descriptor.
5
Is there any additional information available for CVE-2015-2929?
Yes, you can find additional information about CVE-2015-2929 at the following references: [1] and [2].