ID

VAR-201401-0740


TITLE

Tor has multiple denial of service vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2014-00065

DESCRIPTION

Tor is an implementation of the second generation of onion routing, through which users can communicate anonymously over the Internet. Tor has multiple denial of service vulnerabilities. An attacker could exploit these vulnerabilities to cause an affected application to crash, resulting in a denial of service

Trust: 0.81

sources: CNVD: CNVD-2014-00065 // BID: 64650

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-00065

AFFECTED PRODUCTS

vendor:tormodel:0.2.4.11-alphascope: - version: -

Trust: 0.6

vendor:tormodel:0.2.4.15-rcscope: - version: -

Trust: 0.3

vendor:tormodel:0.2.4.12-alphascope: - version: -

Trust: 0.3

vendor:tormodel:0.2.4.16-rcscope:neversion: -

Trust: 0.3

vendor:tormodel:0.2.4.13-alphascope:neversion: -

Trust: 0.3

sources: CNVD: CNVD-2014-00065 // BID: 64650

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2014-00065
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2014-00065
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2014-00065

THREAT TYPE

network

Trust: 0.3

sources: BID: 64650

TYPE

Failure to Handle Exceptional Conditions

Trust: 0.3

sources: BID: 64650

PATCH

title:Tor has multiple patches for denial of service vulnerabilitiesurl:https://www.cnvd.org.cn/patchinfo/show/42145

Trust: 0.6

sources: CNVD: CNVD-2014-00065

EXTERNAL IDS

db:BIDid:64650

Trust: 0.9

db:CNVDid:CNVD-2014-00065

Trust: 0.6

sources: CNVD: CNVD-2014-00065 // BID: 64650

REFERENCES

url:http://www.securityfocus.com/bid/64650

Trust: 0.6

url:https://trac.torproject.org/projects/tor/ticket/8833

Trust: 0.3

url:https://trac.torproject.org/projects/tor/ticket/9063

Trust: 0.3

url:https://trac.torproject.org/projects/tor/ticket/9337

Trust: 0.3

url:https://gitweb.torproject.org/tor.git/commit/11f1b7d9dfa8434c629339220ed47f87a957344b

Trust: 0.3

url:https://gitweb.torproject.org/tor.git/blob_plain/head:/changelog

Trust: 0.3

url:https://gitweb.torproject.org/tor.git/commit/139d367f297575a59b96b64a633ed2b6988d60e1

Trust: 0.3

url:http://www.torproject.org/index.html.en

Trust: 0.3

sources: CNVD: CNVD-2014-00065 // BID: 64650

CREDITS

nickm, torland, Roger, Rob Jansen and Florian Tschorsch

Trust: 0.3

sources: BID: 64650

SOURCES

db:CNVDid:CNVD-2014-00065
db:BIDid:64650

LAST UPDATE DATE

2022-05-17T01:48:03.329000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-00065date:2014-01-07T00:00:00
db:BIDid:64650date:2013-10-08T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-00065date:2014-01-07T00:00:00
db:BIDid:64650date:2013-10-08T00:00:00