CVE-2017-8821: Buffer Overflow
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can cause a denial of service (application hang) via crafted PEM input that signifies a public key requiring a password, which triggers an attempt by the OpenSSL library to ask the user for the password, aka TROVE-2017-011.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8821?
CVE-2017-8821 has a high severity rating due to its potential to cause denial of service through application hangs.
How do I fix CVE-2017-8821?
To fix CVE-2017-8821, upgrade to Tor versions 0.3.5.16 or later, or apply the recommended fixes from your operating system's package manager.
Which versions of Tor are affected by CVE-2017-8821?
CVE-2017-8821 affects Tor versions prior to 0.2.5.16 and between 0.2.6 and 0.3.1.8.
Is CVE-2017-8821 present in Debian Linux?
Yes, CVE-2017-8821 is present in specific versions of Tor included in Debian Linux distributions 8.0 and 9.0.
What kind of attack does CVE-2017-8821 enable?
CVE-2017-8821 enables denial of service attacks by causing the application to hang through crafted PEM input.