#VU8851 Information disclosure in Tor - CVE-2017-0380
Published: October 9, 2017 / Updated: October 17, 2017
Tor
tor.eff.org
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists in the rend_service_intro_established() function in 'or/rendservice.c due to the system may log uninitialized stack contents when a certain hidden service error occurs while SafeLogging is disabled. A remote attacker can use an error message about the construction of an introduction point circuit and gain access to potentially sensitive information from uninitialized stack memory.