CVE-2019-8955: High severity tor project tor vulnerability
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-8955.
What is the severity of CVE-2019-8955?
The severity of CVE-2019-8955 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2019-8955?
Tor versions before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha are affected by CVE-2019-8955.
How can a remote denial of service occur with CVE-2019-8955?
A remote denial of service can occur via memory exhaustion in the KIST cell scheduler.
Where can I find more information about CVE-2019-8955?
You can find more information about CVE-2019-8955 at the following references: [http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00013.html](http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00013.html), [http://www.securityfocus.com/bid/107136](http://www.securityfocus.com/bid/107136), [https://blog.torproject.org/new-releases-tor-0402-alpha-0358-03411-and-03312](https://blog.torproject.org/new-releases-tor-0402-alpha-0358-03411-and-03312).