Sploitus

CVE-2012-4922

1 known exploit for CVE-2012-4922

The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed directory object, a different vulnerability than CVE-2012-4419.

Affected products
Tor
Torproject Tor
≤ 0.2.2.38, 0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.6.1, 0.0.6.2, 0.0.7, 0.0.7.1, 0.0.7.2, 0.0.7.3, 0.0.8.1, 0.0.9.1, 0.0.9.2, 0.0.9.3, 0.0.9.4, 0.0.9.5, 0.0.9.6, 0.0.9.7, 0.0.9.8, 0.0.9.9, 0.0.9.10, 0.1.0.10, 0.1.0.11, 0.1.0.12, 0.1.0.13, 0.1.0.14, 0.1.0.15, 0.1.0.16, 0.1.0.17, 0.1.1.20, 0.1.1.21, 0.1.1.22, 0.1.1.23, 0.1.1.24, 0.1.1.25, 0.1.1.26, 0.1.2.13, 0.1.2.14
CVSS 2.0
5.0 MEDIUM
EPSS
2.2% (81th percentile)
Weakness
CWE-20
NVD status
Modified
Published
2012-09-14
CVE-2012-4922 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2012-4922

Proof-of-concept code and exploit modules indexed by Sploitus