Tor Onion Service Descriptor resource consumption
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.3epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown function of the component Onion Service Descriptor Handler. Performing manipulation results in resource consumption. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is considered difficult. Upgrading to version 0.4.8.18 and 0.4.9.3-alpha is recommended to address this issue. It is recommended to upgrade the affected component.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X
Affected products
n/a · TorReferences
https://forum.torproject.org/t/alpha-and-stable-release-0-4-8-18-and-0-4-9-3-alpha/20578https://github.com/chunmianwang/Tordoshttps://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.8/ReleaseNoteshttps://vuldb.com/?ctiid.324814https://vuldb.com/?id.324814https://vuldb.com/?submit.640605