cbcvebase.
CVE-2008-5397
published 2008-12-09

CVE-2008-5397: Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging…

PriorityP425high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.36%
28.3th percentile
Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.

Affected

105 ranges· showing 25
VendorProductVersion rangeFixed in
debiantor< tor 0.2.0.32-1 (bookworm)tor 0.2.0.32-1 (bookworm)
tortor<= 0.1.2.31
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor
tortor

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.