CVE-2018-0490

UnknownEPSS 2.73%

Last modified

CVE-2018-0490 is a vulnerability of currently unknown severity. An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service (NULL pointer dereference and directory-authority crash) via a misformatted relay descriptor that is mishandled during voting.. EPSS estimates a 2.73% chance of exploitation in the next 30 days.

Description

An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service (NULL pointer dereference and directory-authority crash) via a misformatted relay descriptor that is mishandled during voting.

Metrics

EPSS Probability
2.73%

84.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
TorprojectTor<= 0.2.9.14
TorprojectTor>= 0.3.1.7, <= 0.3.1.9
TorprojectTor0.3.1.1Alpha
TorprojectTor0.3.1.2Alpha
TorprojectTor0.3.1.3Alpha
TorprojectTor0.3.1.4Alpha
TorprojectTor0.3.1.5Alpha
TorprojectTor0.3.1.6Rc
TorprojectTor0.3.2.1Alpha
TorprojectTor0.3.2.2Alpha
TorprojectTor0.3.2.3Alpha
TorprojectTor0.3.2.4Alpha
TorprojectTor0.3.2.5Alpha
TorprojectTor0.3.2.6Alpha
TorprojectTor0.3.2.7Rc
TorprojectTor0.3.2.8Rc
TorprojectTor0.3.2.9
DebianDebian Linux9.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-0490?
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service (NULL pointer dereference and directory-authority crash) via a misformatted relay descriptor that is mishandled during voting.
How severe is CVE-2018-0490?
Severity scoring for CVE-2018-0490 is pending analysis. The EPSS model estimates a 2.73% probability of exploitation in the next 30 days.
How do I fix CVE-2018-0490?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-0490?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST