ID

VAR-201101-0101


CVE

CVE-2011-0427


TITLE

Tor Heap-based buffer overflow vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2011-004109

DESCRIPTION

Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. Tor is a second generation of onion routing implementation. The TOR project team patched Tor multiple security vulnerabilities, including heap overflow allowing arbitrary code execution (CVE-2011-0427). Zlib compression processing has a denial of service vulnerability, but some key memory is not properly zero initialized before release. Causes leakage of critical memory information. Tor is prone to a heap-based buffer-overflow vulnerability, a denial-of-service vulnerability, and an information-disclosure vulnerability. ---------------------------------------------------------------------- Secure your corporate defenses and reduce complexity in handling vulnerability threats with the new Secunia Vulnerability Intelligence Manager (VIM). Request a free trial: http://secunia.com/products/corporate/vim/ ---------------------------------------------------------------------- TITLE: Tor Multiple Vulnerabilities SECUNIA ADVISORY ID: SA42907 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/42907/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=42907 RELEASE DATE: 2011-01-19 DISCUSS ADVISORY: http://secunia.com/advisories/42907/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/42907/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=42907 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: A weakness and two vulnerabilities have been reported in Tor, which can be exploited by malicious, local users to disclose potentially sensitive information, and by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system. 1) An unspecified error can be exploited to cause a heap-based memory corruption. 2) An error within the handling of zlib-compressed data can be exploited to cause a DoS by sending specially crafted compressed data. 3) Various functions do not properly clear keys from memory before freeing them, which may lead to the disclosure of the keys. The weakness and the vulnerabilities are reported in versions prior to 0.2.1.29. SOLUTION: Update to version 0.2.1.29. PROVIDED AND/OR DISCOVERED BY: The vendor credits: 1) debuger 2) doorss 3) cypherpunks ORIGINAL ADVISORY: http://blog.torproject.org/blog/tor-02129-released-security-patches 2) https://trac.torproject.org/projects/tor/ticket/2324 3) https://trac.torproject.org/projects/tor/ticket/2384 https://trac.torproject.org/projects/tor/ticket/2385 OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ EXPLOIT: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ---------------------------------------------------------------------- . For more information: SA42907 SOLUTION: Apply updated packages via the apt-get package manager. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2148-1 security@debian.org http://www.debian.org/security/ Moritz Muehlenhoff January 17, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tor Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2011-0427 The developers of Tor, an anonymizing overlay network for TCP, found three security issues during a security audit. The Debian Security Tracker will be updated once they're available: http://security-tracker.debian.org/tracker/source-package/tor For the stable distribution (lenny), this problem has been fixed in version 0.2.1.29-1~lenny+1. For the testing distribution (squeeze) and the unstable distribution (sid), this problem has been fixed in version 0.2.1.29-1. For the experimental distribution, this problem has been fixed in version 0.2.2.21-alpha-1. We recommend that you upgrade your tor packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAk00jUQACgkQXm3vHE4uylpElQCdGeCpaq6kGaUtHXwyKbj4WjMe Uk0AoLm9PBi6oSAqFsicw4h6M9y6gCha =NFbb -----END PGP SIGNATURE----- . Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/tor < 0.2.1.30 >= 0.2.1.30 Description =========== Multiple vulnerabilities have been discovered in Tor. Please review the CVE identifiers referenced below for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Tor users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/tor-0.2.1.30" NOTE: This is a legacy GLSA. Updates for all affected architectures are available since April 2, 2011. It is likely that your system is already no longer affected by this issue. References ========== [ 1 ] CVE-2011-0015 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0015 [ 2 ] CVE-2011-0016 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0016 [ 3 ] CVE-2011-0427 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0427 [ 4 ] CVE-2011-0490 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0490 [ 5 ] CVE-2011-0491 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0491 [ 6 ] CVE-2011-0492 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0492 [ 7 ] CVE-2011-0493 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0493 [ 8 ] CVE-2011-1924 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1924 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201110-13.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2011 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5

Trust: 2.79

sources: NVD: CVE-2011-0427 // JVNDB: JVNDB-2011-004109 // CNVD: CNVD-2011-0204 // BID: 45832 // PACKETSTORM: 97644 // PACKETSTORM: 97622 // PACKETSTORM: 97616 // PACKETSTORM: 105951

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2011-0204

AFFECTED PRODUCTS

vendor:tormodel:torscope:eqversion:0.0.7

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.7.1

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.6.1

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.6.2

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.5

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.3

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.6

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.7.3

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.4

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.7.2

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.2.1.20

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.9.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.8.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.28

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre21

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.9.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.32

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.31

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.9.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.26

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.29

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.22

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre27

Trust: 1.0

vendor:tormodel:torscope:lteversion:0.2.1.28

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.27

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.27

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre24

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.26

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.24

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.30

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.9.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.25

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.31

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.9.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.9.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.25

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.9.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.20

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.9.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.34

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.21

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.33

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.20

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.35

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.26

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.20

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre22

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.9.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.22

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.24

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.22

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.30

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.25

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.21

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre25

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre26

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.9.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2_pre20

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.21

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.28

Trust: 0.9

vendor:the tormodel:torscope:eqversion:0.2.2.21-alpha

Trust: 0.8

vendor:the tormodel:torscope:ltversion:0.2.2.x

Trust: 0.8

vendor:gentoomodel:linuxscope: - version: -

Trust: 0.3

vendor:debianmodel:linux sparcscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux s/390scope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux powerpcscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux mipselscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux mipsscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux m68kscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux ia-64scope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux ia-32scope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux hppascope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux armelscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux armscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux amd64scope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux alphascope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linuxscope:eqversion:5.0

Trust: 0.3

vendor:tormodel:torscope:neversion:0.2.1.29

Trust: 0.3

sources: CNVD: CNVD-2011-0204 // BID: 45832 // JVNDB: JVNDB-2011-004109 // CNNVD: CNNVD-201101-213 // NVD: CVE-2011-0427

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2011-0427
value: MEDIUM

Trust: 1.0

NVD: CVE-2011-0427
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201101-213
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2011-0427
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2011-004109 // CNNVD: CNNVD-201101-213 // NVD: CVE-2011-0427

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.8

sources: JVNDB: JVNDB-2011-004109 // NVD: CVE-2011-0427

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 105951 // CNNVD: CNNVD-201101-213

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201101-213

CONFIGURATIONS

sources: JVNDB: JVNDB-2011-004109

PATCH

title:tor-02129-released-security-patchesurl:http://blog.torproject.org/blog/tor-02129-released-security-patches

Trust: 0.8

title:Tor unexplained buffer overflow, patch for denial of service and information disclosure vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/2615

Trust: 0.6

sources: CNVD: CNVD-2011-0204 // JVNDB: JVNDB-2011-004109

EXTERNAL IDS

db:NVDid:CVE-2011-0427

Trust: 3.5

db:BIDid:45832

Trust: 1.3

db:SECUNIAid:42907

Trust: 1.1

db:SECUNIAid:42905

Trust: 1.1

db:VUPENid:ADV-2011-0132

Trust: 1.0

db:VUPENid:ADV-2011-0131

Trust: 1.0

db:SECTRACKid:1024980

Trust: 1.0

db:JVNDBid:JVNDB-2011-004109

Trust: 0.8

db:CNVDid:CNVD-2011-0204

Trust: 0.6

db:CNNVDid:CNNVD-201101-213

Trust: 0.6

db:PACKETSTORMid:97644

Trust: 0.1

db:PACKETSTORMid:97622

Trust: 0.1

db:PACKETSTORMid:97616

Trust: 0.1

db:PACKETSTORMid:105951

Trust: 0.1

sources: CNVD: CNVD-2011-0204 // BID: 45832 // JVNDB: JVNDB-2011-004109 // PACKETSTORM: 97644 // PACKETSTORM: 97622 // PACKETSTORM: 97616 // PACKETSTORM: 105951 // CNNVD: CNNVD-201101-213 // NVD: CVE-2011-0427

REFERENCES

url:http://blog.torproject.org/blog/tor-02129-released-security-patches

Trust: 1.4

url:http://secunia.com/advisories/42907

Trust: 1.0

url:http://www.securitytracker.com/id?1024980

Trust: 1.0

url:http://www.debian.org/security/2011/dsa-2148

Trust: 1.0

url:http://secunia.com/advisories/42905

Trust: 1.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/64748

Trust: 1.0

url:https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/changelog

Trust: 1.0

url:http://www.vupen.com/english/advisories/2011/0132

Trust: 1.0

url:http://archives.seul.org/or/announce/jan-2011/msg00000.html

Trust: 1.0

url:http://www.vupen.com/english/advisories/2011/0131

Trust: 1.0

url:http://www.securityfocus.com/bid/45832

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2011-0427

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2011-0427

Trust: 0.8

url:http://blog.torproject.org/blog/tor-02129-released-security-patcheshttp

Trust: 0.6

url:http://www.torproject.org/index.html.en

Trust: 0.3

url:http://secunia.com/products/corporate/evm/

Trust: 0.2

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.2

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.2

url:http://secunia.com/products/corporate/vim/

Trust: 0.2

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.2

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.2

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-0427

Trust: 0.2

url:https://trac.torproject.org/projects/tor/ticket/2384

Trust: 0.1

url:https://trac.torproject.org/projects/tor/ticket/2324

Trust: 0.1

url:http://secunia.com/advisories/42907/

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=42907

Trust: 0.1

url:http://secunia.com/advisories/42907/#comments

Trust: 0.1

url:https://trac.torproject.org/projects/tor/ticket/2385

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=42905

Trust: 0.1

url:http://www.us.debian.org/security/2011/dsa-2148

Trust: 0.1

url:http://secunia.com/advisories/42905/#comments

Trust: 0.1

url:http://secunia.com/advisories/42905/

Trust: 0.1

url:http://www.debian.org/security/faq

Trust: 0.1

url:http://www.debian.org/security/

Trust: 0.1

url:http://security-tracker.debian.org/tracker/source-package/tor

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0016

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0493

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0493

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0016

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0490

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0015

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0490

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0491

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0492

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1924

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0015

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0427

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0491

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1924

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0492

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://security.gentoo.org/glsa/glsa-201110-13.xml

Trust: 0.1

sources: CNVD: CNVD-2011-0204 // BID: 45832 // JVNDB: JVNDB-2011-004109 // PACKETSTORM: 97644 // PACKETSTORM: 97622 // PACKETSTORM: 97616 // PACKETSTORM: 105951 // NVD: CVE-2011-0427

CREDITS

debuger, doorss and cypherpunks.

Trust: 0.3

sources: BID: 45832

SOURCES

db:CNVDid:CNVD-2011-0204
db:BIDid:45832
db:JVNDBid:JVNDB-2011-004109
db:PACKETSTORMid:97644
db:PACKETSTORMid:97622
db:PACKETSTORMid:97616
db:PACKETSTORMid:105951
db:CNNVDid:CNNVD-201101-213
db:NVDid:CVE-2011-0427

LAST UPDATE DATE

2025-04-11T23:02:12.317000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-0204date:2013-09-06T00:00:00
db:BIDid:45832date:2015-05-07T17:14:00
db:JVNDBid:JVNDB-2011-004109date:2012-03-27T00:00:00
db:CNNVDid:CNNVD-201101-213date:2011-01-20T00:00:00
db:NVDid:CVE-2011-0427date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CNVDid:CNVD-2011-0204date:2011-01-18T00:00:00
db:BIDid:45832date:2011-01-17T00:00:00
db:JVNDBid:JVNDB-2011-004109date:2012-03-27T00:00:00
db:PACKETSTORMid:97644date:2011-01-18T10:02:22
db:PACKETSTORMid:97622date:2011-01-18T01:26:35
db:PACKETSTORMid:97616date:2011-01-18T21:19:09
db:PACKETSTORMid:105951date:2011-10-18T19:42:05
db:CNNVDid:CNNVD-201101-213date:2011-01-20T00:00:00
db:NVDid:CVE-2011-0427date:2011-01-19T12:00:19.750