Release date: 2011-12-16
Updated on: 2011-12-19
Affected Systems:
Debian Linux 6.0 x
Debian Linux 5.0 x
Tor 0.2.x
Tor 0.1.x
Tor 0.0.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51097
Cve id: CVE-2011-2778
The Onion Router is an implementation of The second generation of Onion routing. Users can communicate anonymously on The Internet through The Tor.
A heap buffer overflow vulnerability exists in Tor implementation. Remote attackers who successfully exploit this vulnerability can execute arbitrary code with the current user permission.
<* Source: Debian Linux advisory
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Tor
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://tor.eff.org/