CVE-2016-8860: Buffer Overflow
Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buft data had NUL termination, but the implementation of or/buffers.c did not ensure that NUL termination was present, which allows remote attackers to cause a denial of service (client, hidden service, relay, or authority crash) via crafted data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8860?
CVE-2016-8860 is classified as a denial of service vulnerability.
How do I fix CVE-2016-8860?
To fix CVE-2016-8860, update Tor to version 0.2.9.4-alpha or later.
What versions of Tor are affected by CVE-2016-8860?
CVE-2016-8860 affects all Tor versions before 0.2.8.9 and all 0.2.9.x versions before 0.2.9.4-alpha.
What can attackers do with CVE-2016-8860?
Attackers can exploit CVE-2016-8860 to cause a denial of service, affecting both clients and hidden services.
How can I determine if I'm at risk from CVE-2016-8860?
If you're using an affected version of Tor, you are at risk from CVE-2016-8860.