CVE-2017-0380

NameCVE-2017-0380
DescriptionThe rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attackers to obtain sensitive information by leveraging access to the log files of a hidden service, because uninitialized stack data is included in an error message about construction of an introduction point circuit.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-3993-1
Debian Bugs876221

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tor (PTS)buster0.3.5.16-1fixed
buster (security)0.3.5.16-1+deb10u1fixed
bullseye (security), bullseye0.4.5.16-1fixed
bookworm, bookworm (security)0.4.7.16-1fixed
sid, trixie0.4.8.10-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
torsourcewheezy(not affected)
torsourcejessie(not affected)
torsourcestretch0.2.9.12-1DSA-3993-1
torsource(unstable)0.3.1.7-1876221

Notes

[jessie] - tor <not-affected> (Issue introduced in 0.2.7.2-alpha)
[wheezy] - tor <not-affected> (Issue introduced in 0.2.7.2-alpha)
https://trac.torproject.org/projects/tor/ticket/23490
https://gitweb.torproject.org/tor.git/commit/?id=09ea89764a4d3a907808ed7d4fe42abfe64bd486

Search for package or bug name: Reporting problems