buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.
The product does not handle or incorrectly handles an exceptional condition.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tor | Torproject | * | 0.2.4.26 (excluding) |
Tor | Torproject | 0.2.5.1 (including) | 0.2.5.11 (excluding) |
Tor | Ubuntu | precise | * |
Tor | Ubuntu | trusty | * |
Tor | Ubuntu | upstream | * |
Tor | Ubuntu | utopic | * |
Tor | Ubuntu | vivid | * |