CVE-2017-0380: Medium severity tor project tor vulnerability
The rendserviceintroestablished function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attackers to obtain sensitive information by leveraging access to the log files of a hidden service, because uninitialized stack data is included in an error message about construction of an introduction point circuit.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0380?
The severity of CVE-2017-0380 is classified as medium, as it may allow attackers to obtain sensitive information under certain conditions.
How do I fix CVE-2017-0380?
To fix CVE-2017-0380, upgrade to a patched version of Tor, specifically 0.2.8.15 or later, or 0.3.1.7 or later.
What software versions are affected by CVE-2017-0380?
CVE-2017-0380 affects Tor versions before 0.2.8.15, 0.2.9.x before 0.2.9.12, and low versions of 0.3.x up to 0.3.2.1-alpha.
Can CVE-2017-0380 be exploited remotely?
Yes, CVE-2017-0380 could potentially be exploited remotely if SafeLogging is disabled.
What type of vulnerability is CVE-2017-0380?
CVE-2017-0380 is an information disclosure vulnerability in the Tor service.