Vulnerabilities > CVE-2009-0939 - Denial of Service vulnerability in Tor

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
tor
critical
nessus

Summary

Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0.

Nessus

NASL familyGentoo Local Security Checks
NASL idGENTOO_GLSA-200904-11.NASL
descriptionThe remote host is affected by the vulnerability described in GLSA-200904-11 (Tor: Multiple vulnerabilities) Theo de Raadt reported that the application does not properly drop privileges to the primary groups of the user specified via the
last seen2020-06-01
modified2020-06-02
plugin id36139
published2009-04-11
reporterThis script is Copyright (C) 2009-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/36139
titleGLSA-200904-11 : Tor: Multiple vulnerabilities