In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "0.3.3.12"
},
{
"introduced": "0.3.4.8"
},
{
"fixed": "0.3.4.11"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.4.0-alpha\\-dev"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.4.1-alpha"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.4.2-alpha"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.4.3-alpha"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.4.4-rc"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.4.5-rc"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.4.6-rc"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.4.7-rc"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.5.0-alpha\\-dev"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.5.1-alpha"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.5.2-alpha"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.5.3-alpha"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.5.4-alpha"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.5.5-alpha"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.5.6-rc"
},
{
"introduced": "0"
},
{
"last_affected": "0.3.5.7"
},
{
"introduced": "0"
},
{
"last_affected": "0.4.0.1-alpha"
}
]
}