CVE-2012-3518
Publication date 26 August 2012
Last updated 24 July 2024
Ubuntu priority
Description
The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, which allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted (1) vote document or (2) consensus document.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| tor | ||
| 16.04 LTS xenial |
Fixed 0.2.3.22-rc-1
|
|
| 14.04 LTS trusty |
Fixed 0.2.3.22-rc-1
|
|
Notes
Patch details
| Package | Patch details |
|---|---|
| tor |