Vulnerability CVE-2019-8955: Information

Description

In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.

Severity: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Feb. 22, 2019
Modified: Aug. 24, 2020
Error type identifier: CWE-770

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
torsisyphus0.3.5.8-alt10.4.8.6-alt1ALT-PU-2019-1291-1222461Fixed
torp100.3.5.8-alt10.4.8.6-alt1ALT-PU-2019-1291-1222461Fixed
torp90.3.5.8-alt10.4.3.6-alt1ALT-PU-2019-1291-1222461Fixed
torc10f10.3.5.8-alt10.4.7.13-alt1ALT-PU-2019-1291-1222461Fixed
torc9f20.3.5.8-alt10.4.3.6-alt1ALT-PU-2019-1291-1222461Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*
      End excliding
      0.3.3.12

      cpe:2.3:a:torproject:tor:0.3.4.0:alpha-dev:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.4.1:alpha:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.4.2:alpha:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.4.3:alpha:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.4.4:rc:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.4.5:rc:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.4.6:rc:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.4.7:rc:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*
      Start including
      0.3.4.8
      End excliding
      0.3.4.11

      cpe:2.3:a:torproject:tor:0.3.5.0:alpha-dev:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.5.1:alpha:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.5.2:alpha:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.5.3:alpha:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.5.4:alpha:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.5.5:alpha:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.5.6:rc:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.3.5.7:*:*:*:*:*:*:*

      cpe:2.3:a:torproject:tor:0.4.0.1:alpha:*:*:*:*:*:*