Input validation error in Tor - CVE-2017-8822

 

Input validation error in Tor - CVE-2017-8822

Published: December 3, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU37869
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8822
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.


Affected software

Tor
Arch Linux
Fedora
tor

How to mitigate CVE-2017-8822

Install update from vendor's website.

Tor - update to 0.3.1.9
tor - addressed in versions 0.2.9.14-1.el6, 0.2.9.14-1.el7, 0.3.1.9-1.fc26, 0.3.1.9-1.fc27

External References

Related Security Bulletins