Candidate: CVE-2019-8955 PublicDate: 2019-02-21 23:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8955 https://blog.torproject.org/new-releases-tor-0402-alpha-0358-03411-and-03312 https://trac.torproject.org/projects/tor/ticket/29168 Description: In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_tor: upstream: https://github.com/torproject/tor/commit/be84ed1a64ed7ce810bd3924fa96c2588b491ef5 upstream_tor: released (0.3.5.8-1, 0.4.0.2-alpha) precise/esm_tor: DNE trusty_tor: not-affected (code not present) trusty/esm_tor: not-affected (code not present) xenial_tor: not-affected (code not present) bionic_tor: needed cosmic_tor: ignored (reached end-of-life) disco_tor: not-affected (0.3.5.8-1) eoan_tor: not-affected (0.3.5.8-1) focal_tor: not-affected (0.3.5.8-1) groovy_tor: not-affected (0.3.5.8-1) hirsute_tor: not-affected (0.3.5.8-1) impish_tor: not-affected (0.3.5.8-1) jammy_tor: not-affected (0.3.5.8-1) devel_tor: not-affected (0.3.5.8-1)