CVE-2024-35312

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-35312
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-35312.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-35312
Aliases
Published
2024-05-17T22:15:07Z
Modified
2024-11-29T23:49:55.514241Z
Summary
[none]
Details

In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003.

References

Affected packages

Git / gitlab.torproject.org/tpo/core/arti

Affected ranges

Type
GIT
Repo
https://gitlab.torproject.org/tpo/core/arti
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

arti-1.*

arti-1.2.1

arti-v0.*

arti-v0.0.0
arti-v0.0.1
arti-v0.0.2
arti-v0.0.3
arti-v0.0.4
arti-v0.1.0
arti-v0.2.0
arti-v0.3.0
arti-v0.4.0
arti-v0.5.0
arti-v0.6.0

arti-v1.*

arti-v1.0.0
arti-v1.0.1
arti-v1.1.0
arti-v1.1.1
arti-v1.1.10
arti-v1.1.11
arti-v1.1.12
arti-v1.1.13
arti-v1.1.2
arti-v1.1.3
arti-v1.1.4
arti-v1.1.5
arti-v1.1.6
arti-v1.1.7
arti-v1.1.8
arti-v1.1.9
arti-v1.2.0
arti-v1.2.1
arti-v1.2.2

tor-dirmgr-v0.*

tor-dirmgr-v0.5.1

tor-llcrypto-v0.*

tor-llcrypto-v0.4.4