CVE-2012-5573

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
01/01/2013
Last modified:
11/04/2025

Description

The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption or excessive cell reception rate) or bypass intended flow-control restrictions via a RELAY_COMMAND_SENDME command.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:torproject:tor:*:rc:*:*:*:*:*:* 0.2.3.24 (including)
cpe:2.3:a:torproject:tor:0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre13:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre14:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre15:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre16:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre17:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre18:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre19:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre20:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre21:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre22:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre23:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre24:*:*:*:*:*:*
cpe:2.3:a:torproject:tor:0.0.2:pre25:*:*:*:*:*:*