CVE-2008-5397
published 2008-12-09CVE-2008-5397: Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging…
PriorityP425high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.36%
28.3th percentile
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.
Affected
105 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.2.0.32-1 (bookworm) | tor 0.2.0.32-1 (bookworm) |
| tor | tor | <= 0.1.2.31 | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tor: does not properly process User/Group configuration options (privilege escalation)
vendor_redhat·2008-12-04·CVSS 7.2
CVE-2008-5397 [HIGH] tor: does not properly process User/Group configuration options (privilege escalation)
tor: does not properly process User/Group configuration options (privilege escalation)
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.
Debian
CVE-2008-5397: tor - Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configu...
vendor_debian·2008·CVSS 7.2
CVE-2008-5397 [HIGH] CVE-2008-5397: tor - Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configu...
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.
Scope: local
bookworm: resolved (fixed in 0.2.0.32-1)
bullseye: resolved (fixed in 0.2.0.32-1)
forky: resolved (fixed in 0.2.0.32-1)
sid: resolved (fixed in 0.2.0.32-1)
trixie: resolved (fixed in 0.2.0.32-1)
GHSA
GHSA-f53f-xhf2-gxr5: Tor before 0
ghsa_unreviewed·2022-05-17
CVE-2008-5397 [HIGH] GHSA-f53f-xhf2-gxr5: Tor before 0
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.
OSV
CVE-2008-5397: Tor before 0
osv·2008-12-09·CVSS 7.2
CVE-2008-5397 [HIGH] CVE-2008-5397: Tor before 0
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.
No detection rules found.
No public exploits indexed.
http://blog.torproject.org/blog/tor-0.2.0.32-releasedhttp://secunia.com/advisories/33025http://secunia.com/advisories/34583http://security.gentoo.org/glsa/glsa-200904-11.xmlhttp://www.securityfocus.com/bid/32648http://www.vupen.com/english/advisories/2008/3366https://exchange.xforce.ibmcloud.com/vulnerabilities/47101http://blog.torproject.org/blog/tor-0.2.0.32-releasedhttp://secunia.com/advisories/33025http://secunia.com/advisories/34583http://security.gentoo.org/glsa/glsa-200904-11.xmlhttp://www.securityfocus.com/bid/32648http://www.vupen.com/english/advisories/2008/3366https://exchange.xforce.ibmcloud.com/vulnerabilities/47101
2008-12-09
Published