5
CVE-2011-0015
- EPSS 3.11%
- Veröffentlicht 19.01.2011 12:00:06
- Zuletzt bearbeitet 16.06.2026 23:26:37
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allows remote attackers to cause a denial of service via a large compression factor.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.11% | 0.861 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://archives.seul.org/or/announce/Jan-2011/msg00000.html
http://blog.torproject.org/blog/tor-02129-released-security-patches
http://secunia.com/advisories/42905
http://secunia.com/advisories/42907
http://www.debian.org/security/2011/dsa-2148
http://www.openwall.com/lists/oss-security/2011/01/18/7
http://www.securityfocus.com/bid/45832
http://www.securitytracker.com/id?1024980
http://www.vupen.com/english/advisories/2011/0131
http://www.vupen.com/english/advisories/2011/0132
https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLog
https://trac.torproject.org/projects/tor/ticket/2324