CVE-2017-0380

The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attackers to obtain sensitive information by leveraging access to the log files of a hidden service, because uninitialized stack data is included in an error message about construction of an introduction point circuit.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
debianCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
VendorProductVersion
torprojecttor
𝑥
≤ 0.2.8.14
torprojecttor
0.2.9.0
torprojecttor
0.2.9.0:alpha
torprojecttor
0.2.9.1:alpha
torprojecttor
0.2.9.2:alpha
torprojecttor
0.2.9.3:alpha
torprojecttor
0.2.9.4:alpha
torprojecttor
0.2.9.5:alpha
torprojecttor
0.2.9.6
torprojecttor
0.2.9.8
torprojecttor
0.2.9.9
torprojecttor
0.2.9.10
torprojecttor
0.2.9.11
torprojecttor
0.3.0.0
torprojecttor
0.3.0.1:alpha
torprojecttor
0.3.0.2:alpha
torprojecttor
0.3.0.3:alpha
torprojecttor
0.3.0.4:rc
torprojecttor
0.3.0.5:rc
torprojecttor
0.3.0.6
torprojecttor
0.3.0.7
torprojecttor
0.3.0.8
torprojecttor
0.3.0.9
torprojecttor
0.3.0.10
torprojecttor
0.3.1.1:alpha
torprojecttor
0.3.1.2:alpha
torprojecttor
0.3.1.3:alpha
torprojecttor
0.3.1.4:alpha
torprojecttor
0.3.1.5:alpha
torprojecttor
0.3.1.6:alpha
torprojecttor
0.3.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tor
bullseye (security)
0.4.5.16-1
fixed
bullseye
0.4.5.16-1
fixed
jessie
not-affected
wheezy
not-affected
bookworm
0.4.7.16-1
fixed
bookworm (security)
0.4.7.16-1
fixed
sid
0.4.8.13-2
fixed
trixie
0.4.8.13-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tor
bionic
not-affected
artful
Fixed 0.3.0.13-0ubuntu1~17.10.2
released
zesty
ignored
xenial
Fixed 0.2.9.14-1ubuntu1~16.04.2
released
trusty
not-affected