HIGH
debian/tor.init in the Debian tor_0.2.9.11-1~deb9u1 package for Tor was designed to execute aa-exec from the standard system pathname if the apparmor package is installed, but implements this incorrectly (with a wrong assumption that the specific pathname would remain the same forever), which allows attackers to bypass intended AppArmor restrictions by leveraging the silent loss of this protection mechanism
Published Jul 23, 2017
7.5
HIGHCVSS 3.0
EPSS 1.26%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.