Candidate: CVE-2016-1254 PublicDate: 2017-12-05 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1254 https://blog.torproject.org/blog/tor-02812-released https://trac.torproject.org/projects/tor/ticket/21018 Description: Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor. Ubuntu-Description: It was discovered that the Tor client could be made to crash via a crafted hidden service descriptor. This could result in a denial of service. Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=848847 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_tor: upstream_tor: released (0.2.9.8-2) precise_tor: ignored (reached end-of-life) precise/esm_tor: DNE (precise was needs-triage) trusty_tor: released (0.2.4.27-1ubuntu0.1) trusty/esm_tor: released (0.2.4.27-1ubuntu0.1) vivid/stable-phone-overlay_tor: DNE vivid/ubuntu-core_tor: DNE xenial_tor: not-affected (0.2.9.14-1ubuntu1~16.04.2) yakkety_tor: ignored (reached end-of-life) zesty_tor: ignored (reached end-of-life) artful_tor: ignored (reached end-of-life) bionic_tor: not-affected (0.3.2.10-1) cosmic_tor: not-affected (0.3.3.9-1) devel_tor: not-affected (0.3.3.9-1)