LWN.net Logo

tor: denial of service

Package(s):tor CVE #(s):CVE-2012-4922
Created:October 2, 2012 Updated:February 4, 2013
Description: From the CVE entry:

The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed directory object, a different vulnerability than CVE-2012-4419.

Alerts:
openSUSE openSUSE-SU-2012:1278-1 2012-10-02
Gentoo 201301-03 2013-01-08
Fedora FEDORA-2012-14650 2013-02-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds