5
CVE-2011-1924
- EPSS 2.82%
- Veröffentlicht 14.06.2011 17:55:05
- Zuletzt bearbeitet 16.06.2026 23:30:22
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory authority crash) via a crafted policy that triggers creation of a long port list.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.82% | 0.847 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://lists.fedoraproject.org/pipermail/package-announce/2011-June/061258.html
http://secunia.com/advisories/43548
http://secunia.com/advisories/44862
http://www.securityfocus.com/bid/46618
https://bugzilla.redhat.com/show_bug.cgi?id=705192
https://bugzilla.redhat.com/show_bug.cgi?id=705194
https://gitweb.torproject.org/tor.git/commit/43414eb98821d3b5c6c65181d7545ce938f82c8e
https://lists.torproject.org/pipermail/tor-announce/2011-February/000000.html