PT-2020-14500 · Openssl+4 · Openssl+4

Published

2019-05-07

·

Updated

2024-06-15

·

CVE-2020-15572

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tor versions prior to 0.4.3.6
Description The issue is caused by an out-of-bounds memory access, allowing a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS). This problem only occurs when Tor is built with the NSS library, which requires the "--enable-nss" flag, as Tor is compiled with OpenSSL by default.
Recommendations For Tor versions prior to 0.4.3.6, update to version 0.4.3.6 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the NSS library by compiling Tor with OpenSSL, which is the default configuration.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1777
ALT-PU-2020-2340
ALT-PU-2020-2702
CVE-2020-15572
OPENSUSE-SU-2020:1970-1
OPENSUSE-SU-2020_1970-1
OPENSUSE-SU-2024:11469-1

Affected Products

Alt Linux
Nss
Openssl
Suse
Tor