|
Message-ID: <20121126164857.GB2689@redhat.com> Date: Mon, 26 Nov 2012 09:48:57 -0700 From: Vincent Danen <vdanen@...hat.com> To: oss-security@...ts.openwall.com Subject: tor DoS via SENDME cells I've not seen a CVE for this yet, could one get assigned? It was reported that Tor suffered from a denial of service vulnerability due to an error when handling SENDME cells. This could be exploited to cause excessive consumption of memory resources within an entry node. This is fixed in upstream version 0.2.3.25. References: https://secunia.com/advisories/51329/ https://trac.torproject.org/projects/tor/ticket/6252 https://gitweb.torproject.org/arma/tor.git/commitdiff/b9b54568c0bb64c32bd0b362954bdbc8c1234b16 https://bugzilla.redhat.com/show_bug.cgi?id=880310 https://bugs.gentoo.org/show_bug.cgi?id=444804 Thanks. -- Vincent Danen / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.