CVE-2017-8820: Null Pointer Dereference
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory authorities via a malformed descriptor, aka TROVE-2017-010.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8820?
CVE-2017-8820 has a moderate severity rating as it can cause a denial of service due to a NULL pointer dereference.
How do I fix CVE-2017-8820?
To fix CVE-2017-8820, upgrade to Tor versions 0.2.5.16, 0.2.8.17, 0.2.9.14, 0.3.0.13, or 0.3.1.9 or later.
What versions of Tor are affected by CVE-2017-8820?
CVE-2017-8820 affects Tor versions before 0.2.5.16, between 0.2.6 and 0.2.8.17, between 0.2.9 and 0.2.9.14, between 0.3.0 and 0.3.0.13, and between 0.3.1 and 0.3.1.9.
Can CVE-2017-8820 be exploited remotely?
Yes, CVE-2017-8820 can be exploited remotely by attackers sending malformed descriptors to directory authorities.
Is there any workaround for CVE-2017-8820?
There are no known workarounds for CVE-2017-8820, so updating to a fixed version is the recommended approach.