CVE-2018-0491: Use After Free
Published Mar 5, 2018
·Updated
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.
Affected Software
1 affected component
torproject Tor>=0.3.2.0<0.3.2.10
Remediation
Patch Available
Event History
Mar 5, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-0491?
CVE-2018-0491 is a use-after-free vulnerability that was discovered in Tor 0.3.2.x before 0.3.2.10.
2
How does CVE-2018-0491 impact Tor users?
CVE-2018-0491 allows remote attackers to cause a denial of service (relay crash) in Tor.
3
What is the severity of CVE-2018-0491?
CVE-2018-0491 has a severity rating of 7.5 (High).
4
How can I fix CVE-2018-0491?
To fix CVE-2018-0491, users should update to Tor version 0.3.2.10.
5
Where can I find more information about CVE-2018-0491?
You can find more information about CVE-2018-0491 from the Tor Project's blog and ticket pages.