PT-2022-6632 · Tor+1 · Tor+1

Published

2022-06-17

·

Updated

2024-06-15

·

CVE-2022-33903

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tor versions 0.4.7.x through 0.4.7.7
Description The issue is related to incorrect cleanup or release of resources, which can be exploited by a remote attacker to cause a denial of service via the wedging of RTT estimation. This can potentially impact the anonymity provided by the Tor network.
Recommendations For Tor versions 0.4.7.x through 0.4.7.7, update to version 0.4.7.8 to resolve the issue.

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2070
ALT-PU-2022-2091
BDU:2023-02936
CVE-2022-33903
OPENSUSE-SU-2022:10023-1
OPENSUSE-SU-2024:12149-1

Affected Products

Alt Linux
Tor