CVE-2012-3518
Publication date 26 August 2012
Last updated 24 July 2024
Ubuntu priority
The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, which allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted (1) vote document or (2) consensus document.
Status
Package | Ubuntu Release | Status |
---|---|---|
tor | ||
16.04 LTS xenial |
Fixed 0.2.3.22-rc-1
|
|
14.04 LTS trusty |
Fixed 0.2.3.22-rc-1
|
|
Notes
Patch details
Package | Patch details |
---|---|
tor |