CVE-2007-4097TOR vulnerability

7 documents6 sources
Severity
6.4MEDIUMNVD
EPSS
1.1%
top 22.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 30
Latest updateMay 1

Description

Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitive information, contrary to specifications.

CVSS vector

AV:N/AC:L/C:P/I:N/A:PExploitability: 10.0 | Impact: 4.9

Affected Packages2 packages

Debiantorproject/tor< 0.1.2.15-1+3
NVDtor/tor15 versions+14

Patches

🔴Vulnerability Details

3
GHSA
GHSA-24jh-rrw8-fr8w: Tor before 02022-05-01
OSV
CVE-2007-4097: Tor before 02007-07-30
CVEList
CVE-2007-4097: Tor before 02007-07-30

📋Vendor Advisories

1
Debian
CVE-2007-4097: tor - Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down...2007

💬Community

2
Bugzilla
CVE-2007-0958 core-dumping unreadable binaries via PT_INTERP2007-06-08
Bugzilla
CVE-2007-0958 core-dumping unreadable binaries via PT_INTERP2007-02-23
CVE-2007-4097 — TOR vulnerability | cvebase