cbcvebase.
CVE-2005-2643
published 2005-08-23

CVE-2005-2643: Tor 0.1.0.13 and earlier, and experimental versions 0.1.1.4-alpha and earlier, does not reject certain weak keys when using ephemeral Diffie-Hellman (DH)…

medium5CVSS 3.1
AVNACLAuNCPINAN
Tor 0.1.0.13 and earlier, and experimental versions 0.1.1.4-alpha and earlier, does not reject certain weak keys when using ephemeral Diffie-Hellman (DH) handshakes, which allows malicious Tor servers to obtain the keys that a client uses for other systems in the circuit.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debiantor< tor 0.1.0.14-1 (bookworm)tor 0.1.0.14-1 (bookworm)
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor

CVSS provenance

nvd5.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM