CVE-2006-0414
published 2006-01-25CVE-2006-0414: Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden…
PriorityP421medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.96%
85.7th percentile
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.1.1.11-alpha-1 (bookworm) | tor 0.1.1.11-alpha-1 (bookworm) |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mhf3-xw62-m62g: Tor allows remote attackers to discover the IP address of a hidden service by accessing this service at a high rate, thereby changing the server's CPU
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2006-6893 [MEDIUM] GHSA-mhf3-xw62-m62g: Tor allows remote attackers to discover the IP address of a hidden service by accessing this service at a high rate, thereby changing the server's CPU
Tor allows remote attackers to discover the IP address of a hidden service by accessing this service at a high rate, thereby changing the server's CPU temperature and consequently changing the pattern of time values visible through (1) ICMP timestamps, (2) TCP sequence numbers, and (3) TCP timestamps, a different vulnerability than CVE-2006-0414. NOTE: it could be argued that this is a laws-of-physics vulnerability that is a fundamental design limitation of certain hardware implementations, so perhaps this issue should not be included in CVE.
GHSA
GHSA-cjqp-wrm4-w3h3: Tor before 0
ghsa_unreviewed·2022-05-01
CVE-2006-0414 [MEDIUM] GHSA-cjqp-wrm4-w3h3: Tor before 0
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.
OSV
CVE-2006-6893: Tor allows remote attackers to discover the IP address of a hidden service by accessing this service at a high rate, thereby changing the server's CPU
osv·2006-12-31·CVSS 5.0
CVE-2006-6893 [MEDIUM] CVE-2006-6893: Tor allows remote attackers to discover the IP address of a hidden service by accessing this service at a high rate, thereby changing the server's CPU
Tor allows remote attackers to discover the IP address of a hidden service by accessing this service at a high rate, thereby changing the server's CPU temperature and consequently changing the pattern of time values visible through (1) ICMP timestamps, (2) TCP sequence numbers, and (3) TCP timestamps, a different vulnerability than CVE-2006-0414. NOTE: it could be argued that this is a laws-of-physics vulnerability that is a fundamental design limitation of certain hardware implementations, so perhaps this issue should not be included in CVE.
OSV
CVE-2006-0414: Tor before 0
osv·2006-01-25·CVSS 5.0
CVE-2006-0414 [MEDIUM] CVE-2006-0414: Tor before 0
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.
Debian
CVE-2006-0414: tor - Tor before 0.1.1.20 allows remote attackers to identify hidden services via a ma...
vendor_debian·2006·CVSS 5.0
CVE-2006-0414 [MEDIUM] CVE-2006-0414: tor - Tor before 0.1.1.20 allows remote attackers to identify hidden services via a ma...
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.
Scope: local
bookworm: resolved (fixed in 0.1.1.11-alpha-1)
bullseye: resolved (fixed in 0.1.1.11-alpha-1)
forky: resolved (fixed in 0.1.1.11-alpha-1)
sid: resolved (fixed in 0.1.1.11-alpha-1)
trixie: resolved (fixed in 0.1.1.11-alpha-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.seul.org/or/announce/Jan-2006/msg00001.htmlhttp://secunia.com/advisories/18576http://secunia.com/advisories/20514http://security.gentoo.org/glsa/glsa-200606-04.xmlhttp://tor.eff.org/cvs/tor/ChangeLoghttp://www.osvdb.org/22689http://www.securityfocus.com/bid/18323http://www.securityfocus.com/bid/19795https://exchange.xforce.ibmcloud.com/vulnerabilities/24285http://archives.seul.org/or/announce/Jan-2006/msg00001.htmlhttp://secunia.com/advisories/18576http://secunia.com/advisories/20514http://security.gentoo.org/glsa/glsa-200606-04.xmlhttp://tor.eff.org/cvs/tor/ChangeLoghttp://www.osvdb.org/22689http://www.securityfocus.com/bid/18323http://www.securityfocus.com/bid/19795https://exchange.xforce.ibmcloud.com/vulnerabilities/24285
2006-01-25
Published