CVE-2016-1254: Buffer Overflow
Published Dec 20, 2016
·Updated
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
Affected Software
9 affected componentsFixes available
debian/tor
0.3.5.16-10.3.5.16-1+deb10u10.4.5.16-10.4.7.13-10.4.8.7-1
torproject Tor<0.2.8.12
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Fedoraproject Fedora=24
Fedoraproject Fedora=25
openSUSE Leap=42.2
openSUSE openSUSE=13.2
Opensuse Project Leap=42.1
Remediation
Event History
Dec 20, 2016
Data Sourced
07:03 AM
SeverityAffected Software
Dec 5, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1254?
CVE-2016-1254 has a severity rating that indicates a potential denial of service vulnerability that may crash the Tor client.
2
How do I fix CVE-2016-1254?
To fix CVE-2016-1254, ensure that your Tor software is updated to version 0.2.8.12 or later.
3
Which versions of Tor are affected by CVE-2016-1254?
CVE-2016-1254 affects all versions of Tor prior to 0.2.8.12.
4
What impact does CVE-2016-1254 have on Tor users?
The impact of CVE-2016-1254 on Tor users is the potential for a remote attacker to crash the Tor client.
5
Is CVE-2016-1254 related to hidden services in Tor?
Yes, CVE-2016-1254 is specifically related to crafted hidden service descriptors that can trigger the vulnerability.