REDHAT-BUG-880310: Medium severity tor browser vulnerability
It was reported [1],[2] that Tor suffered from a denial of service vulnerability due to an error when handling SENDME cells. This could be exploited to cause excessive consumption of memory resources within an entry node.
This is fixed in upstream version 0.2.3.25 (git [3]).
[1] https://secunia.com/advisories/51329/ [2] https://trac.torproject.org/projects/tor/ticket/6252 [3] https://gitweb.torproject.org/arma/tor.git/commitdiff/b9b54568c0bb64c32bd0b362954bdbc8c1234b16
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-880310?
The severity of REDHAT-BUG-880310 is categorized as a denial of service vulnerability.
How do I fix REDHAT-BUG-880310?
You can fix REDHAT-BUG-880310 by upgrading to the upstream version 0.2.3.25 of Tor.
What causes the vulnerability REDHAT-BUG-880310?
REDHAT-BUG-880310 is caused by an error when handling SENDME cells, leading to excessive memory consumption.
Which software versions are affected by REDHAT-BUG-880310?
Versions of Tor prior to 0.2.3.25 are affected by the vulnerability REDHAT-BUG-880310.
Who reported the REDHAT-BUG-880310 vulnerability?
The vulnerability REDHAT-BUG-880310 was reported by users within the Tor community.