Candidate: CVE-2015-2689 PublicDate: 2020-01-24 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2689 https://bugs.torproject.org/14129 Description: Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets. Ubuntu-Description: Notes: sbeattie> DoS due to DNS triggering an abort Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_tor: upstream_tor: released (0.2.5.11-1) lucid_tor: DNE precise_tor: ignored (reached end-of-life) precise/esm_tor: DNE (precise was needed) trusty_tor: released (0.2.4.27-1build0.14.04.1) trusty/esm_tor: released (0.2.4.27-1build0.14.04.1) utopic_tor: ignored (reached end-of-life) vivid_tor: released (0.2.5.12-1build0.15.04.1) vivid/stable-phone-overlay_tor: DNE vivid/ubuntu-core_tor: DNE wily_tor: not-affected (0.2.6.10-1) xenial_tor: not-affected (0.2.6.10-1) yakkety_tor: not-affected (0.2.6.10-1) zesty_tor: not-affected (0.2.6.10-1) devel_tor: not-affected (0.2.6.10-1)