PT-2022-6632 · Tor+1 · Tor+1
Published
2022-06-17
·
Updated
2024-06-15
·
CVE-2022-33903
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Tor versions 0.4.7.x through 0.4.7.7
Description
The issue is related to incorrect cleanup or release of resources, which can be exploited by a remote attacker to cause a denial of service via the wedging of RTT estimation. This can potentially impact the anonymity provided by the Tor network.
Recommendations
For Tor versions 0.4.7.x through 0.4.7.7, update to version 0.4.7.8 to resolve the issue.
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Tor