CVE-2012-5573: Torproject Tor
Medium severity, CVSS 5.0. EPSS: 3.1% chance of exploitation in the next 30 days.
The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption or excessive cell reception rate) or bypass intended flow-control restrictions via a RELAY_COMMAND_SENDME command.
Affected products
- Torproject Tor: up to and including 0.2.3.24; version 0.0.2 only; version 0.0.3 only; version 0.0.4 only; version 0.0.5 only; version 0.0.6 only; …
Published 2013-01-01. Last modified 2026-06-16.