5
CVE-2012-3518
- EPSS 2.78%
- Veröffentlicht 26.08.2012 03:17:44
- Zuletzt bearbeitet 16.06.2026 23:43:23
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, which allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted (1) vote document or (2) consensus document.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.78% | 0.845 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://lists.opensuse.org/opensuse-updates/2012-08/msg00048.html
http://openwall.com/lists/oss-security/2012/08/21/6
http://security.gentoo.org/glsa/glsa-201301-03.xml
https://lists.torproject.org/pipermail/tor-announce/2012-August/000086.html
http://secunia.com/advisories/50583
https://gitweb.torproject.org/tor.git/commit/55f635745afacefffdaafc72cc176ca7ab817546
https://gitweb.torproject.org/tor.git/commit/57e35ad3d91724882c345ac709666a551a977f0f
https://trac.torproject.org/projects/tor/ticket/6530