CVE-2017-0380
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attackers to obtain sensitive information by leveraging access to the log files of a hidden service, because uninitialized stack data is included in an error message about construction of an introduction point circuit.
La funciĆ³n rend_service_intro_established en or/rendservice.c en versiones de Tor anteriores a la 0.2.8.15, versiones 0.2.9.x anteriores a la 0.2.9.12, versiones 0.3.0.x anteriores a la 0.3.0.11, versiones 0.3.1.x anteriores a la 0.3.1.7 y versiones 0.3.2.x anteriores a la 0.3.2.1-alpha, cuando se deshabilita SafeLogging, permite a los atacantes obtener informaciĆ³n sensible mediante el acceso al archivo de registro de un servicio oculto. Esto se debe a que los datos de la pila sin inicializar se incluyen en un mensaje de error sobre el punto de entrada a la red.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-11-29 CVE Reserved
- 2017-09-18 CVE Published
- 2023-05-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-532: Insertion of Sensitive Information into Log File
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1039519 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/torproject/tor/commit/09ea89764a4d3a907808ed7d4fe42abfe64bd486 | 2017-11-06 | |
https://trac.torproject.org/projects/tor/ticket/23490 | 2017-11-06 |
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2017/dsa-3993 | 2017-11-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | <= 0.2.8.14 Search vendor "Torproject" for product "Tor" and version " <= 0.2.8.14" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.9.0 Search vendor "Torproject" for product "Tor" and version "0.2.9.0" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.9.0 Search vendor "Torproject" for product "Tor" and version "0.2.9.0" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.9.1 Search vendor "Torproject" for product "Tor" and version "0.2.9.1" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.9.2 Search vendor "Torproject" for product "Tor" and version "0.2.9.2" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.9.3 Search vendor "Torproject" for product "Tor" and version "0.2.9.3" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.9.4 Search vendor "Torproject" for product "Tor" and version "0.2.9.4" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.9.5 Search vendor "Torproject" for product "Tor" and version "0.2.9.5" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.9.6 Search vendor "Torproject" for product "Tor" and version "0.2.9.6" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.9.8 Search vendor "Torproject" for product "Tor" and version "0.2.9.8" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.9.9 Search vendor "Torproject" for product "Tor" and version "0.2.9.9" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.9.10 Search vendor "Torproject" for product "Tor" and version "0.2.9.10" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.9.11 Search vendor "Torproject" for product "Tor" and version "0.2.9.11" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.0.0 Search vendor "Torproject" for product "Tor" and version "0.3.0.0" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.0.1 Search vendor "Torproject" for product "Tor" and version "0.3.0.1" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.0.2 Search vendor "Torproject" for product "Tor" and version "0.3.0.2" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.0.3 Search vendor "Torproject" for product "Tor" and version "0.3.0.3" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.0.4 Search vendor "Torproject" for product "Tor" and version "0.3.0.4" | rc |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.0.5 Search vendor "Torproject" for product "Tor" and version "0.3.0.5" | rc |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.0.6 Search vendor "Torproject" for product "Tor" and version "0.3.0.6" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.0.7 Search vendor "Torproject" for product "Tor" and version "0.3.0.7" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.0.8 Search vendor "Torproject" for product "Tor" and version "0.3.0.8" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.0.9 Search vendor "Torproject" for product "Tor" and version "0.3.0.9" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.0.10 Search vendor "Torproject" for product "Tor" and version "0.3.0.10" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.1.1 Search vendor "Torproject" for product "Tor" and version "0.3.1.1" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.1.2 Search vendor "Torproject" for product "Tor" and version "0.3.1.2" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.1.3 Search vendor "Torproject" for product "Tor" and version "0.3.1.3" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.1.4 Search vendor "Torproject" for product "Tor" and version "0.3.1.4" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.1.5 Search vendor "Torproject" for product "Tor" and version "0.3.1.5" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.1.6 Search vendor "Torproject" for product "Tor" and version "0.3.1.6" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.2 Search vendor "Torproject" for product "Tor" and version "0.3.2" | - |
Affected
|