cbcvebase.
CVE-2007-4097
published 2007-07-30

CVE-2007-4097: Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitive information…

medium6.4CVSS 3.1
AVNACLAuNCPINAP
Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitive information, contrary to specifications.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiantor< tor 0.1.2.15-1 (bookworm)tor 0.1.2.15-1 (bookworm)
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
torprojecttor>= 0 < 0.1.2.15-10.1.2.15-1
torprojecttor>= 0 < 0.1.2.15-10.1.2.15-1
torprojecttor>= 0 < 0.1.2.15-10.1.2.15-1
torprojecttor>= 0 < 0.1.2.15-10.1.2.15-1

CVSS provenance

nvd6.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.4MEDIUM