
Descriptiondebian/tor.init in the Debian tor_0.2.9.11-1~deb9u1 package for Tor was designed to execute aa-exec from the standard system pathname if the apparmor package is installed, but implements this incorrectly (with a wrong assumption that the specific pathname would remain the same forever), which allows attackers to bypass intended AppArmor restrictions by leveraging the silent loss of this protection mechanism. NOTE: this does not affect systems, such as default Debian stretch installations, on which Tor startup relies on a systemd unit file (instead of this tor.init script).
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs869153

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tor (PTS)jessie, jessie (lts)
stretch (security), stretch (lts)
buster (security)
bullseye (security), bullseye0.4.5.16-1fixed
bookworm (security), bookworm0.4.7.16-1fixed
sid, trixie0.4.8.11-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
torsourcewheezy(not affected)
torsourcejessie(not affected)


[stretch] - tor <no-dsa> (Minor issue)
[jessie] - tor <not-affected> (aa-exec in jessie is located in /usr/sbin/)
[wheezy] - tor <not-affected> (aa-exec in jessie is located in /usr/sbin/)

