7.5
CVE-2026-77642
- EPSS -
- Veröffentlicht 20.08.2026 21:15:49
- Zuletzt bearbeitet 20.08.2026 22:18:06
- CVE-Watchlists
- Unerledigt
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellertorproject
≫
Produkt
Tor
Default Statusunaffected
Version
0.2.8.2-alpha
Version <
0.4.9.9
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 7.5 | 2.2 | 4.7 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.9/ChangeLog