Tor Directory Authority 'src/or/policies.c' Denial of Service Vulnerability
BID:46618
Info
Tor Directory Authority 'src/or/policies.c' Denial of Service Vulnerability
| Bugtraq ID: | 46618 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-1924 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2011 12:00AM |
| Updated: | Apr 13 2015 09:28PM |
| Credit: | piebeer |
| Vulnerable: |
Tor Tor 0.2.1.29 Tor Tor 0.2.1.28 Tor Tor 0.2.1.27 Tor Tor 0.2.1.22 Tor Tor 0.2.1.21 Tor Tor 0.2.1.20 Gentoo Linux |
| Not Vulnerable: |
Tor Tor 0.2.1.30 |
Discussion
Tor Directory Authority 'src/or/policies.c' Denial of Service Vulnerability
Tor is prone to a denial-of-service vulnerability that affects directory authority.
Attackers can exploit this issue to crash the affected application, denying service to legitimate users.
Versions prior to Tor 0.2.1.30 are vulnerable.
Tor is prone to a denial-of-service vulnerability that affects directory authority.
Attackers can exploit this issue to crash the affected application, denying service to legitimate users.
Versions prior to Tor 0.2.1.30 are vulnerable.
Exploit / POC
Tor Directory Authority 'src/or/policies.c' Denial of Service Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Tor Directory Authority 'src/or/policies.c' Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Tor Directory Authority 'src/or/policies.c' Denial of Service Vulnerability
References:
References:
- [tor-announce] Tor 0.2.1.30 is released (Tor)
- Tor Homepage (Tor Project)