Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian: DSA-2548-1 Medium Severity: Mitigations for Tor DoS Attack

debian
Calendar Grey September 13, 2012
Debian Logo
Numerous weaknesses identified in the Tor network necessitate urgent action to avert service disruptions and potential threats to security.
Severel vulnerabilities have been discovered in Tor, an online privacy tool

Summary

Severel vulnerabilities have been discovered in Tor, an online privacy
tool.

CVE-2012-3518

Avoid an uninitialised memory read when reading a vote or consensus
document that has an unrecognized flavour name. This could lead to
a remote, resulting in denial of service.

CVE-2012-3519

Try to leak less information about what relays a client is choosing to
a side-channel attacker.

CVE-2012-4419

By providing specially crafted date strings to a victim tor instance,
an attacker can cause it to run into an assertion and shut down

Additionally the update to stable includes the following fixes:
- - When waiting for a client to renegotiate, don't allow it to add any
bytes to the input buffer. This fixes a potential DoS issue
[tor-5934, tor-6007].

For the stable distribution (squeeze), these problems have been fixed in
version 0.2.2.39-1.

For the unstable distribution, these problems have been fixed in version
0.2.3.22-rc-1.

We recommend that you upgrade your tor packages.

Further information abou...

Read the Full Advisory

Severity
medium
Lowest
Low
Medium
High
Critical

Package: tor
CVE ID: CVE-2012-3518 CVE-2012-3519 CVE-2012-4419

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here