{"id":"MGASA-2017-0176","summary":"Updated tor packages fix security vulnerability","details":"A remotely triggerable assertion failure caused by receiving a\nBEGIN_DIR cell on a hidden service rendezvous circuit (CVE-2017-0376).\n","modified":"2026-04-16T06:25:09.365683947Z","published":"2017-06-14T15:52:21Z","upstream":["CVE-2017-0376"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2017-0176.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=21056"},{"type":"WEB","url":"https://blog.torproject.org/blog/tor-0308-released-fix-hidden-services-also-are-02429-02514-02612-0278-02814-and-02911"}],"affected":[{"package":{"name":"tor","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/tor?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.8.14-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0176.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}