MEDIUM
The compare_tor_addr_to_addr_policy function in or/policies.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.21-rc, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a zero-valued port field that is not properly handled during policy comparison
Published Sep 14, 2012
5.0
MEDIUMCVSS 2.0
EPSS 2.16%
Description
The compare_tor_addr_to_addr_policy function in or/policies.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.21-rc, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a zero-valued port field that is not properly handled during policy comparison.
Affected products
No data.
OR
- ≤ 0.2.2.38
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.2
- 0.0.3
- 0.0.4
- 0.0.5
- 0.0.6
- 0.0.6.1
- 0.0.6.2
- 0.0.7
- 0.0.7.1
- 0.0.7.2
- 0.0.7.3
- 0.0.8.1
- 0.0.9.1
- 0.0.9.2
- 0.0.9.3
- 0.0.9.4
- 0.0.9.5
- 0.0.9.6
- 0.0.9.7
- 0.0.9.8
- 0.0.9.9
- 0.0.9.10
- 0.1.0.10
- 0.1.0.11
- 0.1.0.12
- 0.1.0.13
- 0.1.0.14
- 0.1.0.15
- 0.1.0.16
- 0.1.0.17
- 0.1.1.20
- 0.1.1.21
- 0.1.1.22
- 0.1.1.23
- 0.1.1.24
- 0.1.1.25
- 0.1.1.26
- 0.1.2.13
- 0.1.2.14
- 0.1.2.15
- 0.1.2.16
- 0.1.2.17
- 0.1.2.18
- 0.1.2.19
- 0.2.0.30
- 0.2.0.31
- 0.2.0.32
- 0.2.0.33
- 0.2.0.34
- 0.2.0.35
- 0.2.2.18
- 0.2.2.19
- 0.2.2.20
- 0.2.2.21
- 0.2.2.22
- 0.2.2.23
- 0.2.2.24
- 0.2.2.25
- 0.2.2.26
- 0.2.2.27
- 0.2.2.28
- 0.2.2.29
- 0.2.2.30
- 0.2.2.31
- 0.2.2.32
- 0.2.2.33
- 0.2.2.34
- 0.2.2.35
- 0.2.2.36
- 0.2.2.37
- 0.2.3
- 0.2.3.13
- 0.2.3.14
- 0.2.3.15
- 0.2.3.16
- 0.2.3.17
- 0.2.3.18
- 0.2.3.19
- 0.2.3.20
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (9)
- http://lists.fedoraproject.org/pipermail/package-announce/2012-September/088006.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-updates/2012-10/msg00005.html vendor-advisoryx_refsource_SUSE
- http://openwall.com/lists/oss-security/2012/09/13/2 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/50583 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-201301-03.xml vendor-advisoryx_refsource_GENTOO
- https://gitweb.torproject.org/tor.git/blob/release-0.2.2:/ReleaseNotes x_refsource_CONFIRM
- https://gitweb.torproject.org/tor.git/commit/62d96284f7e0f81c40d5df7e53dd7b4dfe7e56a5 x_refsource_CONFIRM
- https://lists.torproject.org/pipermail/tor-talk/2012-September/025434.html mailing-listx_refsource_MLIST
- https://trac.torproject.org/projects/tor/ticket/6690 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| http://lists.fedoraproject.org/pipermail/package-announce/2012-September/088006.html | vendor-advisoryx_refsource_FEDORA | |
| http://lists.opensuse.org/opensuse-updates/2012-10/msg00005.html | vendor-advisoryx_refsource_SUSE | |
| http://openwall.com/lists/oss-security/2012/09/13/2 | mailing-listx_refsource_MLIST | |
| http://secunia.com/advisories/50583 | third-party-advisoryx_refsource_SECUNIA | |
| http://security.gentoo.org/glsa/glsa-201301-03.xml | vendor-advisoryx_refsource_GENTOO | |
| https://gitweb.torproject.org/tor.git/blob/release-0.2.2:/ReleaseNotes | x_refsource_CONFIRM | |
| https://gitweb.torproject.org/tor.git/commit/62d96284f7e0f81c40d5df7e53dd7b4dfe7e56a5 | x_refsource_CONFIRM | |
| https://lists.torproject.org/pipermail/tor-talk/2012-September/025434.html | mailing-listx_refsource_MLIST | |
| https://trac.torproject.org/projects/tor/ticket/6690 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 14, 2012
Updated Aug 6, 2024
Reserved Aug 21, 2012
Link CVE-2012-4419
CISA Vulnrichment
Updated n/a