Denial of Service Vulnerability in Tor from Tor Project
CVE-2016-8860

7.5HIGH

Key Information:

Vendor

Torproject

Status
Vendor
CVE Published:
4 January 2017

What is CVE-2016-8860?

In previous versions of Tor, certain internal functions assumed that data buffers were properly NUL terminated. This oversight allowed remote attackers to craft data that could exploit this flaw, leading to a denial of service. Such an attack could result in crashes affecting clients, hidden services, relays, or the authority, thus compromising the stability and security of the Tor network.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.