CVE-2006-3411
published 2006-07-07CVE-2006-3411: TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers…
PriorityP420medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.29%
67.0th percentile
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.
Affected
73 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.1.1.20-1 (bookworm) | tor 0.1.1.20-1 (bookworm) |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv6.4MEDIUM
vendor_debian6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2006-3411: tor - TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS ...
vendor_debian·2006·CVSS 6.4
CVE-2006-3411 [MEDIUM] CVE-2006-3411: tor - TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS ...
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.
Scope: local
bookworm: resolved (fixed in 0.1.1.20-1)
bullseye: resolved (fixed in 0.1.1.20-1)
forky: resolved (fixed in 0.1.1.20-1)
sid: resolved (fixed in 0.1.1.20-1)
trixie: resolved (fixed in 0.1.1.20-1)
GHSA
GHSA-jpgq-8f9m-vxm2: TLS handshakes in Tor before 0
ghsa_unreviewed·2022-05-01
CVE-2006-3411 [MEDIUM] GHSA-jpgq-8f9m-vxm2: TLS handshakes in Tor before 0
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.
OSV
CVE-2006-3411: TLS handshakes in Tor before 0
osv·2006-07-07·CVSS 6.4
CVE-2006-3411 [MEDIUM] CVE-2006-3411: TLS handshakes in Tor before 0
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2006-07-07
Published