Bug 1173979 (CVE-2020-15572) - VUL-0: CVE-2020-15572: tor: out-of-bound memory access when built with NSS support
Summary: VUL-0: CVE-2020-15572: tor: out-of-bound memory access when built with NSS su...
Status: RESOLVED WORKSFORME
Alias: CVE-2020-15572
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.1
Hardware: Other Other
: P5 - None : Normal (vote)
Target Milestone: ---
Assignee: Bernhard Wiedemann
QA Contact: E-mail List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-07-10 06:31 UTC by Andreas Stieger
Modified: 2020-11-19 20:27 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2020-07-10 06:31:54 UTC
https://lists.torproject.org/pipermail/tor-announce/2020-July/000202.html
https://trac.torproject.org/projects/tor/ticket/33119

  o Major bugfixes (NSS, security, backport from 0.4.4.2-alpha):
    - Fix a crash due to an out-of-bound memory access when Tor is
      compiled with NSS support. Fixes bug 33119; bugfix on
      0.3.5.1-alpha. This issue is also tracked as TROVE-2020-001
      and CVE-2020-15572.


openSUSE package not built with NSS support.
Comment 1 Andreas Stieger 2020-07-10 06:32:06 UTC
openSUSE package not built with NSS support.
Comment 2 OBSbugzilla Bot 2020-11-13 12:50:22 UTC
This is an autogenerated message for OBS integration:
This bug (1173979) was mentioned in
https://build.opensuse.org/request/show/848334 15.1+15.2+Backports:SLE-12+Backports:SLE-15-SP1+Backports:SLE-15-SP2 / tor
Comment 3 Swamp Workflow Management 2020-11-19 20:25:13 UTC
openSUSE-SU-2020:1970-1: An update that solves three vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1164275,1167013,1167014,1173979,1178741
CVE References: CVE-2020-10592,CVE-2020-10593,CVE-2020-15572
JIRA References: 
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    tor-0.3.5.12-25.1
Comment 4 Swamp Workflow Management 2020-11-19 20:27:43 UTC
openSUSE-SU-2020:1970-1: An update that solves three vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1164275,1167013,1167014,1173979,1178741
CVE References: CVE-2020-10592,CVE-2020-10593,CVE-2020-15572
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    tor-0.4.4.6-lp152.2.3.1
openSUSE Leap 15.1 (src):    tor-0.3.5.12-lp151.2.6.1
openSUSE Backports SLE-15-SP2 (src):    tor-0.4.4.6-bp152.2.3.1
openSUSE Backports SLE-15-SP1 (src):    tor-0.3.5.12-bp151.3.6.1
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    tor-0.3.5.12-25.1