CVE-2020-15572

HIGH

Tor < 0.3.5.11 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS), aka TROVE-2020-001.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_misc
https://trac.torproject.org/projects/tor/wiki/TROVE
Release Notes, Vendor Advisory x_refsource_confirm
https://blog.torproject.org/new-release-tor-03511-0428-0436-security-fixes

Scores

CVSS v3 7.5
EPSS 0.0050
EPSS Percentile 66.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (3)
torproject/tor 0.4.4.0 alpha
torproject/tor 0.4.4.1 alpha
torproject/tor < 0.3.5.11
Published Jul 15, 2020
Tracked Since Feb 18, 2026