Candidate: CVE-2016-8860 PublicDate: 2017-01-04 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8860 https://trac.torproject.org/projects/tor/ticket/20384 https://blog.torproject.org/blog/tor-0289-released-important-fixes https://github.com/torproject/tor/commit/3cea86eb2fbb65949673eb4ba8ebb695c87a57ce http://www.openwall.com/lists/oss-security/2016/10/18/11 Description: Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buf_t data had NUL termination, but the implementation of or/buffers.c did not ensure that NUL termination was present, which allows remote attackers to cause a denial of service (client, hidden service, relay, or authority crash) via crafted data. Ubuntu-Description: It was discovered that Tor improperly NUL terminated data. An attacker could possibly use this to cause a crash and denial of service. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_tor: upstream_tor: released (0.2.8.9-1) precise_tor: ignored (reached end-of-life) precise/esm_tor: DNE (precise was needed) trusty_tor: released (0.2.4.27-1ubuntu0.1) trusty/esm_tor: released (0.2.4.27-1ubuntu0.1) vivid/stable-phone-overlay_tor: DNE vivid/ubuntu-core_tor: DNE xenial_tor: not-affected (0.2.8.9-1ubuntu1) yakkety_tor: ignored (reached end-of-life) zesty_tor: not-affected (0.2.8.9-1ubuntu1) artful_tor: not-affected (0.2.8.9-1ubuntu1) bionic_tor: not-affected (0.2.8.9-1ubuntu1) cosmic_tor: not-affected (0.2.8.9-1ubuntu1) devel_tor: not-affected (0.2.8.9-1ubuntu1)