CVE-2017-0380

EUVD-2017-0734
The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attackers to obtain sensitive information by leveraging access to the log files of a hidden service, because uninitialized stack data is included in an error message about construction of an introduction point circuit.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
Affected Products (NVD)
VendorProductVersion
torprojecttor
𝑥
≤ 0.2.8.14
torprojecttor
0.2.9.0
torprojecttor
0.2.9.0:alpha
torprojecttor
0.2.9.1:alpha
torprojecttor
0.2.9.2:alpha
torprojecttor
0.2.9.3:alpha
torprojecttor
0.2.9.4:alpha
torprojecttor
0.2.9.5:alpha
torprojecttor
0.2.9.6
torprojecttor
0.2.9.8
torprojecttor
0.2.9.9
torprojecttor
0.2.9.10
torprojecttor
0.2.9.11
torprojecttor
0.3.0.0
torprojecttor
0.3.0.1:alpha
torprojecttor
0.3.0.2:alpha
torprojecttor
0.3.0.3:alpha
torprojecttor
0.3.0.4:rc
torprojecttor
0.3.0.5:rc
torprojecttor
0.3.0.6
torprojecttor
0.3.0.7
torprojecttor
0.3.0.8
torprojecttor
0.3.0.9
torprojecttor
0.3.0.10
torprojecttor
0.3.1.1:alpha
torprojecttor
0.3.1.2:alpha
torprojecttor
0.3.1.3:alpha
torprojecttor
0.3.1.4:alpha
torprojecttor
0.3.1.5:alpha
torprojecttor
0.3.1.6:alpha
torprojecttor
0.3.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tor
bookworm
0.4.7.16-1
fixed
bookworm (security)
0.4.7.16-1
fixed
bullseye
0.4.5.16-1
fixed
bullseye (security)
0.4.5.16-1
fixed
jessie
not-affected
sid
0.4.8.13-2
fixed
trixie
0.4.8.13-2
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tor
artful
Fixed 0.3.0.13-0ubuntu1~17.10.2
released
bionic
not-affected
trusty
not-affected
xenial
Fixed 0.2.9.14-1ubuntu1~16.04.2
released
zesty
ignored