tor: denial of service
| Package(s): | tor | CVE #(s): | CVE-2015-2928 CVE-2015-2929 | ||||||||||||||||||||||||||||||||||||
| Created: | April 7, 2015 | Updated: | July 7, 2015 | ||||||||||||||||||||||||||||||||||||
| Description: | From the Arch Linux advisory:
CVE-2015-2928: "disgleirio" discovered that a malicious client could trigger an assertion failure in a Tor instance providing a hidden service, thus rendering the service inaccessible. CVE-2015-2929: "DonnchaC" discovered that Tor clients would crash with an assertion failure upon parsing specially crafted hidden service descriptors. | ||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||
