CVE-2017-0376: High severity tor project tor vulnerability
Published Jun 9, 2017
·Updated
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connectionedgeprocessrelaycell function via a BEGINDIR cell on a rendezvous circuit.
Affected Software
3 affected components
torproject Tor<0.3.0.8
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Event History
Jun 9, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-0376?
CVE-2017-0376 has a moderate severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2017-0376?
To fix CVE-2017-0376, upgrade to Tor version 0.3.0.8 or later.
3
Which versions of Tor are affected by CVE-2017-0376?
CVE-2017-0376 affects all versions of Tor before 0.3.0.8.
4
What systems are impacted by CVE-2017-0376?
CVE-2017-0376 impacts Tor running on Debian GNU/Linux versions 8.0 and 9.0.
5
What type of attack does CVE-2017-0376 facilitate?
CVE-2017-0376 facilitates a denial of service attack through an assertion failure in the connection handling code.