CVE-2010-0385
published 2010-01-25CVE-2010-0385: Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive…
PriorityP420medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.98%
78.4th percentile
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive information about bridge identities and bridge descriptors via a dbg-stability.txt directory query.
Affected
131 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.2.1.22-1 (bookworm) | tor 0.2.1.22-1 (bookworm) |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j8c7-5jh6-f92f: Tor before 0
ghsa_unreviewed·2022-05-02
CVE-2010-0385 [MEDIUM] CWE-200 GHSA-j8c7-5jh6-f92f: Tor before 0
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive information about bridge identities and bridge descriptors via a dbg-stability.txt directory query.
OSV
CVE-2010-0385: Tor before 0
osv·2010-01-25·CVSS 5.0
CVE-2010-0385 [MEDIUM] CVE-2010-0385: Tor before 0
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive information about bridge identities and bridge descriptors via a dbg-stability.txt directory query.
Debian
CVE-2010-0385: tor - Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bri...
vendor_debian·2010·CVSS 5.0
CVE-2010-0385 [MEDIUM] CVE-2010-0385: tor - Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bri...
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive information about bridge identities and bridge descriptors via a dbg-stability.txt directory query.
Scope: local
bookworm: resolved (fixed in 0.2.1.22-1)
bullseye: resolved (fixed in 0.2.1.22-1)
forky: resolved (fixed in 0.2.1.22-1)
sid: resolved (fixed in 0.2.1.22-1)
trixie: resolved (fixed in 0.2.1.22-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
bugzilla·2011-01-20·CVSS 5.0
CVE-2011-0015 [MEDIUM] CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 CVE-2010-1676 CVE-2010-0383 CVE-2010-0385 tor various flaws [epel-5]
epel-5 tracking bug for tor: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-1676
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=671259,665046
---
Adding parent bug CVE-2010-0383
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=671259,665046,557798
---
Adding parent bug 705192
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?
Bugzilla
CVE-2010-0383, CVE-2010-0385: tor multiple vulnerabilities in versions prior to 0.2.1.22
bugzilla·2010-01-22·CVSS 5.0
CVE-2010-0383 [MEDIUM] CVE-2010-0383, CVE-2010-0385: tor multiple vulnerabilities in versions prior to 0.2.1.22
CVE-2010-0383, CVE-2010-0385: tor multiple vulnerabilities in versions prior to 0.2.1.22
An updated version of tor (0.2.1.22) is available that updates identity keys for two breached directory authorities [1]. Two of the seven directory authorities for Tor were compromised, leading to migrated servers that require new identity keys. Upstream has recommended that all Tor users upgrade to the latest version in response to this security breach of their servers.
This would affect Fedora 11, 12, rawhide, and EPEL5. Packages for Fedora with this new version are currently in testing, but not for EPEL5.
[1] http://archives.seul.org/or/talk/Jan-2010/msg00161.html
Discussion:
I don't know how easy or difficult it might be to change the current packages in testing from a bugfix update to a secur
http://archives.seul.org/or/announce/Jan-2010/msg00000.htmlhttp://archives.seul.org/or/talk/Jan-2010/msg00162.htmlhttp://secunia.com/advisories/38198http://www.osvdb.org/61865http://www.securityfocus.com/bid/37901http://archives.seul.org/or/announce/Jan-2010/msg00000.htmlhttp://archives.seul.org/or/talk/Jan-2010/msg00162.htmlhttp://secunia.com/advisories/38198http://www.osvdb.org/61865http://www.securityfocus.com/bid/37901
2010-01-25
Published