CVE-2010-0383
published 2010-01-25CVE-2010-0383: Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for…
PriorityP421medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.67%
74.2th percentile
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man-in-the-middle attackers to compromise the anonymity of traffic sources and destinations.
Affected
131 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.2.1.22-1 (bookworm) | tor 0.2.1.22-1 (bookworm) |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-0383: tor - Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity ...
vendor_debian·2010·CVSS 5.0
CVE-2010-0383 [MEDIUM] CVE-2010-0383: tor - Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity ...
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man-in-the-middle attackers to compromise the anonymity of traffic sources and destinations.
Scope: local
bookworm: resolved (fixed in 0.2.1.22-1)
bullseye: resolved (fixed in 0.2.1.22-1)
forky: resolved (fixed in 0.2.1.22-1)
sid: resolved (fixed in 0.2.1.22-1)
trixie: resolved (fixed in 0.2.1.22-1)
GHSA
GHSA-rgxv-h9h8-fc97: Tor before 0
ghsa_unreviewed·2022-05-02
CVE-2010-0383 [MEDIUM] CWE-200 GHSA-rgxv-h9h8-fc97: Tor before 0
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man-in-the-middle attackers to compromise the anonymity of traffic sources and destinations.
OSV
CVE-2010-0383: Tor before 0
osv·2010-01-25·CVSS 5.0
CVE-2010-0383 [MEDIUM] CVE-2010-0383: Tor before 0
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man-in-the-middle attackers to compromise the anonymity of traffic sources and destinations.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
bugzilla·2011-01-20·CVSS 5.0
CVE-2011-0015 [MEDIUM] CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
epel-5 tracking bug for tor: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-1676
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=671259,665046
---
Adding parent bug CVE-2010-0383
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=671259,665046,557798
---
Adding parent bug 705192
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?
Bugzilla
CVE-2010-0090 JDK unspecified vulnerability in JavaWS/Plugin component
bugzilla·2010-03-31·CVSS 5.8
CVE-2010-0090 [MEDIUM] CVE-2010-0090 JDK unspecified vulnerability in JavaWS/Plugin component
CVE-2010-0090 JDK unspecified vulnerability in JavaWS/Plugin component
Update 19 of Oracle/Sun Java fixes an unspecified vulnerability in the JavaWS/Plugin component (CVE-2010-0090). The CVSSv2 scored upstream is cvss2=5.8/AV:N/AC:M/Au:N/C:N/I:P/A:P
Reference:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/javacpumar2010.html
Discussion:
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0337 https://rhn.redhat.com/errata/RHSA-2010-0337.html
---
This issue has been addressed in following products:
Extras for RHEL 4
Extras for Red Hat Enterprise Linux 5
Via RHSA-2010:0383 https://rhn.redhat.com/errata/RHSA-2010-0383.html
---
This issue has been addressed in following products:
Red H
Bugzilla
CVE-2010-0383, CVE-2010-0385: tor multiple vulnerabilities in versions prior to 0.2.1.22
bugzilla·2010-01-22·CVSS 5.0
CVE-2010-0383 [MEDIUM] CVE-2010-0383, CVE-2010-0385: tor multiple vulnerabilities in versions prior to 0.2.1.22
CVE-2010-0383, CVE-2010-0385: tor multiple vulnerabilities in versions prior to 0.2.1.22
An updated version of tor (0.2.1.22) is available that updates identity keys for two breached directory authorities [1]. Two of the seven directory authorities for Tor were compromised, leading to migrated servers that require new identity keys. Upstream has recommended that all Tor users upgrade to the latest version in response to this security breach of their servers.
This would affect Fedora 11, 12, rawhide, and EPEL5. Packages for Fedora with this new version are currently in testing, but not for EPEL5.
[1] http://archives.seul.org/or/talk/Jan-2010/msg00161.html
Discussion:
I don't know how easy or difficult it might be to change the current packages in testing from a bugfix update to a secur
http://archives.seul.org/or/announce/Jan-2010/msg00000.htmlhttp://archives.seul.org/or/talk/Jan-2010/msg00161.htmlhttp://archives.seul.org/or/talk/Jan-2010/msg00162.htmlhttp://archives.seul.org/or/talk/Jan-2010/msg00165.htmlhttp://osvdb.org/61977http://secunia.com/advisories/38198http://www.securityfocus.com/bid/37901http://archives.seul.org/or/announce/Jan-2010/msg00000.htmlhttp://archives.seul.org/or/talk/Jan-2010/msg00161.htmlhttp://archives.seul.org/or/talk/Jan-2010/msg00162.htmlhttp://archives.seul.org/or/talk/Jan-2010/msg00165.htmlhttp://osvdb.org/61977http://secunia.com/advisories/38198http://www.securityfocus.com/bid/37901
2010-01-25
Published