CVE-2008-5398
published 2008-12-09CVE-2008-5398: Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based…
PriorityP337critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.04%
78.9th percentile
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the destination hostname of a refused stream.
Affected
105 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.2.0.32-1 (bookworm) | tor 0.2.0.32-1 (bookworm) |
| tor | tor | <= 0.1.2.31 | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tor: does not properly process the ClientDNSRejectInternalAddresses configuration option
vendor_redhat·2008-12-04·CVSS 9.3
CVE-2008-5398 [CRITICAL] tor: does not properly process the ClientDNSRejectInternalAddresses configuration option
tor: does not properly process the ClientDNSRejectInternalAddresses configuration option
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the destination hostname of a refused stream.
VMware
Updated service console patches.
vendor_vmware·2008-01-07·CVSS 1.2
CVE-2007-3108 [LOW] Updated service console patches.
VMSA-2008-0001: Updated service console patches.
Updated service console patches. VMware Security Advisory VMware Security Advisory Advisory ID: VMware Security Advisory Synopsis: Updated service console patches. VMware Security Advisory Issue date: VMware Security Advisory Updated on:
CVEs: CVE-2007-3108, CVE-2007-4572, CVE-2007-5116, CVE-2007-5135, CVE-2007-5191, CVE-2007-5360, CVE-2007-5398
Debian
CVE-2008-5398: tor - Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddress...
vendor_debian·2008·CVSS 9.3
CVE-2008-5398 [CRITICAL] CVE-2008-5398: tor - Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddress...
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the destination hostname of a refused stream.
Scope: local
bookworm: resolved (fixed in 0.2.0.32-1)
bullseye: resolved (fixed in 0.2.0.32-1)
forky: resolved (fixed in 0.2.0.32-1)
sid: resolved (fixed in 0.2.0.32-1)
trixie: resolved (fixed in 0.2.0.32-1)
GHSA
GHSA-55x8-g885-q727: Tor before 0
ghsa_unreviewed·2022-05-17
CVE-2008-5398 [HIGH] GHSA-55x8-g885-q727: Tor before 0
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the destination hostname of a refused stream.
OSV
CVE-2008-5398: Tor before 0
osv·2008-12-09·CVSS 9.3
CVE-2008-5398 [CRITICAL] CVE-2008-5398: Tor before 0
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the destination hostname of a refused stream.
No detection rules found.
No public exploits indexed.
http://blog.torproject.org/blog/tor-0.2.0.32-releasedhttp://secunia.com/advisories/33025http://secunia.com/advisories/34583http://security.gentoo.org/glsa/glsa-200904-11.xmlhttp://www.securityfocus.com/bid/32648http://www.vupen.com/english/advisories/2008/3366https://exchange.xforce.ibmcloud.com/vulnerabilities/47102http://blog.torproject.org/blog/tor-0.2.0.32-releasedhttp://secunia.com/advisories/33025http://secunia.com/advisories/34583http://security.gentoo.org/glsa/glsa-200904-11.xmlhttp://www.securityfocus.com/bid/32648http://www.vupen.com/english/advisories/2008/3366https://exchange.xforce.ibmcloud.com/vulnerabilities/47102
2008-12-09
Published