MGASA-2020-0165

Source
https://advisories.mageia.org/MGASA-2020-0165.html
Import Source
https://advisories.mageia.org/MGASA-2020-0165.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0165
Related
Published
2020-04-15T10:12:14Z
Modified
2020-04-15T09:44:06Z
Summary
Updated tor packages fix security vulnerabilities
Details

Updated tor package fixes security vulnerabilities:

Tor before 0.3.5.10 allows remote attackers to cause a Denial of Service (CPU consumption) (CVE-2020-10592).

Tor before 0.3.5.10 allows remote attackers to cause a Denial of Service (memory leak). This occurs in circpadsetupmachineoncirc because a circuit-padding machine can be negotiated twice on the same circuit (CVE-2020-10593).

References
Credits

Affected packages