VDB
DEBIAN-CVE-2015-2689
DEBIAN-CVE-2015-2689
PUBLISHED
CVSS 7.5 HIGH
Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | tor | 0, 0, 0 |
| Debian:12 | tor | 0, 0, 0 |
| Debian:11 | tor | 0, 0, 0 |
| Debian:13 | tor | 0, 0, 0 |
Timeline
- Jan 24, 2020 CVE Published
- Apr 28, 2026 CVE Updated