CVE-2007-4098
published 2007-07-30CVE-2007-4098: Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject…
PriorityP426medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
1.90%
77.3th percentile
Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.1.2.15-1 (bookworm) | tor 0.1.2.15-1 (bookworm) |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| torproject | tor | >= 0 < 0.1.2.15-1 | 0.1.2.15-1 |
| torproject | tor | >= 0 < 0.1.2.15-1 | 0.1.2.15-1 |
| torproject | tor | >= 0 < 0.1.2.15-1 | 0.1.2.15-1 |
| torproject | tor | >= 0 < 0.1.2.15-1 | 0.1.2.15-1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7rwq-85qc-qq76: Tor before 0
ghsa_unreviewed·2022-05-01
CVE-2007-4098 [MEDIUM] GHSA-7rwq-85qc-qq76: Tor before 0
Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.
OSV
CVE-2007-4098: Tor before 0
osv·2007-07-30·CVSS 5.8
CVE-2007-4098 [MEDIUM] CVE-2007-4098: Tor before 0
Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.
Debian
CVE-2007-4098: tor - Tor before 0.1.2.15 does not properly distinguish "streamids from different exit...
vendor_debian·2007·CVSS 5.8
CVE-2007-4098 [MEDIUM] CVE-2007-4098: tor - Tor before 0.1.2.15 does not properly distinguish "streamids from different exit...
Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.
Scope: local
bookworm: resolved (fixed in 0.1.2.15-1)
bullseye: resolved (fixed in 0.1.2.15-1)
forky: resolved (fixed in 0.1.2.15-1)
sid: resolved (fixed in 0.1.2.15-1)
trixie: resolved (fixed in 0.1.2.15-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.seul.org/or/announce/Jul-2007/msg00000.htmlhttp://osvdb.org/46970http://secunia.com/advisories/26140http://www.securityfocus.com/bid/25035http://www.vupen.com/english/advisories/2007/2634http://archives.seul.org/or/announce/Jul-2007/msg00000.htmlhttp://osvdb.org/46970http://secunia.com/advisories/26140http://www.securityfocus.com/bid/25035http://www.vupen.com/english/advisories/2007/2634
2007-07-30
Published