DescriptionThe tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed directory object, a different vulnerability than CVE-2012-4419.
Overall state of this security issue: Postponed
This issue is currently rated as having moderate severity.
|National Vulnerability Database|
- openSUSE-SU-2012:1278-1, published Tue, 2 Oct 2012 10:08:38 +0200 (CEST)
List of released packages
|Product(s)||Fixed package version(s)||References|
|openSUSE Tumbleweed|| ||Patchnames:
openSUSE Tumbleweed GA tor