CVE Vulnerabilities

CVE-2015-2688

Improper Handling of Exceptional Conditions

Published: Jan 24, 2020 | Modified: Jan 31, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

buf_pullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Tor Torproject * 0.2.4.26 (excluding)
Tor Torproject 0.2.5.1 (including) 0.2.5.11 (excluding)
Tor Ubuntu precise *
Tor Ubuntu trusty *
Tor Ubuntu upstream *
Tor Ubuntu utopic *
Tor Ubuntu vivid *

References