Remote Denial-of-Service Vulnerability in Tor with Mozilla Network Security Services (NSS)

Remote Denial-of-Service Vulnerability in Tor with Mozilla Network Security Services (NSS)

CVE-2020-15572 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Tor before 0.4.3.6 has an out-of-bounds memory access that allows a remote denial-of-service (crash) attack against Tor instances built to use Mozilla Network Security Services (NSS), aka TROVE-2020-001.

Learn more about our Network Penetration Testing.