CVE-2019-8955
openSUSE Security Advisory - openSUSE-SU-2019:1107-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.
En Tor, en versiones anteriores a la 0.3.3.12, en las 0.3.4.x anteriores a la 0.3.4.11, en las 0.3.5.x anteriores a la 0.3.5.8 y en las 0.4.x anteriores a la 0.4.0.2-alpha, puede ocurrir una denegación de servicio (DoS) remota contra los clientes Tor, además de reproducciones mediante el agotamiento de memoria en el programador "KIST cell".
An update that fixes one vulnerability is now available. This update for tor to version 0.3.4.11 fixes the following issues. Fixed a vulnerability in the KIST cell scheduler which could lead to memory exhaustion and finally Denial-of-Service.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-02-20 CVE Reserved
- 2019-02-21 CVE Published
- 2024-08-04 CVE Updated
- 2025-07-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/107136 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | < 0.3.3.12 Search vendor "Torproject" for product "Tor" and version " < 0.3.3.12" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | >= 0.3.4.8 < 0.3.4.11 Search vendor "Torproject" for product "Tor" and version " >= 0.3.4.8 < 0.3.4.11" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.4.0 Search vendor "Torproject" for product "Tor" and version "0.3.4.0" | alpha-dev |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.4.1 Search vendor "Torproject" for product "Tor" and version "0.3.4.1" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.4.2 Search vendor "Torproject" for product "Tor" and version "0.3.4.2" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.4.3 Search vendor "Torproject" for product "Tor" and version "0.3.4.3" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.4.4 Search vendor "Torproject" for product "Tor" and version "0.3.4.4" | rc |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.4.5 Search vendor "Torproject" for product "Tor" and version "0.3.4.5" | rc |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.4.6 Search vendor "Torproject" for product "Tor" and version "0.3.4.6" | rc |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.4.7 Search vendor "Torproject" for product "Tor" and version "0.3.4.7" | rc |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.5.0 Search vendor "Torproject" for product "Tor" and version "0.3.5.0" | alpha-dev |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.5.1 Search vendor "Torproject" for product "Tor" and version "0.3.5.1" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.5.2 Search vendor "Torproject" for product "Tor" and version "0.3.5.2" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.5.3 Search vendor "Torproject" for product "Tor" and version "0.3.5.3" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.5.4 Search vendor "Torproject" for product "Tor" and version "0.3.5.4" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.5.5 Search vendor "Torproject" for product "Tor" and version "0.3.5.5" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.5.6 Search vendor "Torproject" for product "Tor" and version "0.3.5.6" | rc |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.3.5.7 Search vendor "Torproject" for product "Tor" and version "0.3.5.7" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.4.0.1 Search vendor "Torproject" for product "Tor" and version "0.4.0.1" | alpha |
Affected
|