cbcvebase.
CVE-2007-4098
published 2007-07-30

CVE-2007-4098: Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject…

medium5.8CVSS 3.1
AVNACMAuNCNIPAP
Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.

Affected

20 ranges
VendorProductVersion rangeFixed in
debiantor< tor 0.1.2.15-1 (bookworm)tor 0.1.2.15-1 (bookworm)
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
torprojecttor>= 0 < 0.1.2.15-10.1.2.15-1
torprojecttor>= 0 < 0.1.2.15-10.1.2.15-1
torprojecttor>= 0 < 0.1.2.15-10.1.2.15-1
torprojecttor>= 0 < 0.1.2.15-10.1.2.15-1

CVSS provenance

nvd5.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.8MEDIUM