CVE-2020-10593

Name
CVE-2020-10593
Description
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory leak), aka TROVE-2020-004. This occurs in circpad_setup_machine_on_circ because a circuit-padding machine can be negotiated twice on the same circuit.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://trac.torproject.org/projects/tor/ticket/33619
GENTOO https://security.gentoo.org/glsa/202003-50
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00045.html
SUSE http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00052.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:* tor >= 0.3.5 < 0.3.5.10
cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:* tor > 0.4.1.0 < 0.4.1.9
cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:* tor > 0.4.2.0 <= 0.4.2.7

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
tor edge-community 0.4.2.7-r0 None fixed
tor edge-community 0.3.5.8-r0 None possibly vulnerable
tor 3.22-community 0.4.2.7-r0 None fixed
tor 3.22-community 0.3.5.8-r0 None possibly vulnerable
tor 3.21-community 0.4.2.7-r0 None fixed
tor 3.20-community 0.4.2.7-r0 None fixed
tor 3.19-community 0.4.2.7-r0 None fixed
tor 3.18-community 0.4.2.7-r0 None fixed
tor 3.17-community 0.4.2.7-r0 None fixed