CVE-2018-0491

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
05/03/2018
Last modified:
26/03/2019

Description

A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:* 0.3.2.0 (including) 0.3.2.10 (excluding)