High severity7.5NVD Advisory· Published Jan 24, 2020· Updated Jun 17, 2026
CVE-2015-2689
CVE-2015-2689
Description
Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*range: <0.2.4.26
- (no CPE)range: <0.2.4.26, <0.2.5.11
- (no CPE)range: before 0.2.4.26
Patches
Vulnerability mechanics
References
2- trac.torproject.org/projects/tor/ticket/14129nvdPatchVendor Advisory
- lists.torproject.org/pipermail/tor-talk/2015-March/037281.htmlnvdMailing ListVendor Advisory
News mentions
0No linked articles in our index yet.