[tor-bugs] #8037 [Tor]: Specialy crafter microdesc could trigger to flush up to 16MB uninited heap allocated memory to media

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Jan 23 21:26:32 UTC 2013


#8037: Specialy crafter microdesc could trigger to flush up to 16MB uninited heap
allocated memory to media
----------------------------+-----------------------------------------------
    Reporter:  cypherpunks  |       Owner:                    
        Type:  defect       |      Status:  reopened          
    Priority:  minor        |   Milestone:  Tor: 0.2.4.x-final
   Component:  Tor          |     Version:                    
  Resolution:               |    Keywords:  tor-client easy   
      Parent:               |      Points:                    
Actualpoints:               |  
----------------------------+-----------------------------------------------

Comment(by cypherpunks):

 {{{
     extrainfo->cache_info.signed_descriptor_body = tor_strndup(s, end-s);
 }}}
 Then need to fix it for consistency too. Non exploitable.

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/8037#comment:6>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list