CVE Vulnerabilities

CVE-2017-8820

NULL Pointer Dereference

Published: Dec 03, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory authorities via a malformed descriptor, aka TROVE-2017-010.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
TorTor_project*0.2.5.16 (excluding)
TorTor_project0.2.6 (including)0.2.8.17 (excluding)
TorTor_project0.2.9 (including)0.2.9.14 (excluding)
TorTor_project0.3.0 (including)0.3.0.13 (excluding)
TorTor_project0.3.1 (including)0.3.1.9 (excluding)
TorUbuntuartful*
TorUbuntuesm-apps/xenial*
TorUbuntuupstream*
TorUbuntuxenial*
TorUbuntuzesty*

Potential Mitigations

References