CVE-2018-0490: Null Pointer Dereference
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service (NULL pointer dereference and directory-authority crash) via a misformatted relay descriptor that is mishandled during voting.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-0490?
CVE-2018-0490 is a vulnerability in Tor that allows remote attackers to cause a denial of service via a misformatted protocol-list subprotocol implementation, resulting in a NULL pointer dereference and directory-authority crash.
What is the severity of CVE-2018-0490?
The severity of CVE-2018-0490 is high, with a CVSS score of 7.5.
How does CVE-2018-0490 impact Tor?
CVE-2018-0490 can cause a denial of service, leading to a crash of the Tor directory authority.
How can I fix CVE-2018-0490?
To fix CVE-2018-0490, it is recommended to update Tor to version 0.3.5.16-1 or later.
Where can I find more information about CVE-2018-0490?
You can find more information about CVE-2018-0490 in the Tor Project's ticket and blog post, as well as the Git commit related to the vulnerability.