[tbb-bugs] #12736 [Applications/Tor Browser]: DLL hijacking vulnerability in TBB

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Aug 24 12:44:29 UTC 2016

#12736: DLL hijacking vulnerability in TBB
 Reporter:  underdoge                           |          Owner:  tbb-team
     Type:  defect                              |         Status:  new
 Priority:  High                                |      Milestone:
Component:  Applications/Tor Browser            |        Version:
 Severity:  Normal                              |     Resolution:
 Keywords:  tbb-security, TorBrowserTeam201608  |  Actual Points:
Parent ID:                                      |         Points:
 Reviewer:                                      |        Sponsor:

Comment (by boklm):

 I didn't try to do some debugging yet, but after looking at the HTTPS
 Everywhere code, I am wondering if it could be caused by the
 NSS.initialize function:

   try {
     sharedLib = tcypes.open(nssPath);
   } catch (e) {


 when `nssPath` is empty when called from:
   try {
   } catch(e) {

Ticket URL: <https://trac.torproject.org/projects/tor/ticket/12736#comment:9>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online

More information about the tbb-bugs mailing list