CVE-2020-10593: High severity tor project tor vulnerability
Published Mar 23, 2020
·Updated
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpadsetupmachineoncirc because a circuit-padding machine can be negotiated twice on the same circuit.
Affected Software
5 affected components
torproject Tor>=0.3.5<0.3.5.10
torproject Tor>0.4.1.0<0.4.1.9
torproject Tor>0.4.2.0<=0.4.2.7
openSUSE Backports SLE=15.0-sp1
openSUSE Leap=15.1
Event History
Mar 23, 2020
CVE Published
via MITRE·12:22 PM
Data Sourced
via MITRE·12:22 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-10593.
2
What is the severity of CVE-2020-10593?
The severity of CVE-2020-10593 is high with a score of 7.5.
3
What is the affected software?
The affected software is Tor versions before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7.
4
What is the impact of this vulnerability?
This vulnerability allows remote attackers to cause a Denial of Service through a memory leak.
5
How can I fix CVE-2020-10593?
To fix CVE-2020-10593, update Tor to version 0.3.5.10, 0.4.1.9, or 0.4.2.7.