← Back

CVE-2015-2689

nvd nist
Published: Jan 24, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.

Affected (2)

Products: Torproject: Tor
1 product
Tor
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Torproject
Before 0.2.4.26
From 0.2.5.1 to 0.2.5.11

References (4)

Source: security@debian.org
Mailing ListVendor Advisory
Source: security@debian.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.