PT-2023-35516 · Tor+1 · Tor+1
Published
2023-11-10
·
Updated
2023-11-10
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
tor versions 0.4.7.14 through 0.4.8.7
tor version 0.4.8.8
Description
The issue is related to several bugs and reliability problems in the Tor software, including a crash during handshake with a remote relay when compiled with OpenSSL, expiration of introduction points for onion services, and issues with conflux traffic splitting. The problems can cause connectivity issues for clients and potentially lead to denial-of-service attacks.
Recommendations
For tor versions 0.4.7.14 through 0.4.8.7, update to version 0.4.8.8 to mitigate the issues.
For tor version 0.4.8.8, no additional actions are required as this version already includes the necessary fixes.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl
Tor