PT-2023-35516 · Tor+1 · Tor+1

Published

2023-11-10

·

Updated

2023-11-10

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions tor versions 0.4.7.14 through 0.4.8.7 tor version 0.4.8.8
Description The issue is related to several bugs and reliability problems in the Tor software, including a crash during handshake with a remote relay when compiled with OpenSSL, expiration of introduction points for onion services, and issues with conflux traffic splitting. The problems can cause connectivity issues for clients and potentially lead to denial-of-service attacks.
Recommendations For tor versions 0.4.7.14 through 0.4.8.7, update to version 0.4.8.8 to mitigate the issues. For tor version 0.4.8.8, no additional actions are required as this version already includes the necessary fixes.

Related Identifiers

OPENSUSE-SU-2023:0361-1

Affected Products

Openssl
Tor