Candidate: CVE-2017-0376 PublicDate: 2017-06-09 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0376 https://trac.torproject.org/22494 Description: The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit. Ubuntu-Description: It was discovered that an assertion failure could cause Tor to exit resulting in a denial of service. Notes: sbeattie> introduced in 0.2.2.1-alpha Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864424 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_tor: upstream_tor: released (0.3.0.8, 0.2.9.11) precise/esm_tor: DNE trusty_tor: released (0.2.4.27-1ubuntu0.1) trusty/esm_tor: released (0.2.4.27-1ubuntu0.1) vivid/stable-phone-overlay_tor: DNE vivid/ubuntu-core_tor: DNE xenial_tor: not-affected (0.2.9.11-1~deb9u1) yakkety_tor: ignored (reached end-of-life) zesty_tor: ignored (reached end-of-life) artful_tor: ignored (reached end-of-life) bionic_tor: not-affected (0.3.0.8-1) cosmic_tor: not-affected (0.3.0.8-1) devel_tor: not-affected (0.3.0.8-1)