CVE-2011-2769
published 2011-12-23CVE-2011-2769: Tor before 0.2.2.34, when configured as a bridge, accepts the CREATE and CREATE_FAST values in the Command field of a cell within an OR connection that it…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.20%
64.8th percentile
Tor before 0.2.2.34, when configured as a bridge, accepts the CREATE and CREATE_FAST values in the Command field of a cell within an OR connection that it initiated, which allows remote relays to enumerate bridges by using these values.
Affected
210 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.2.2.34-1 (bookworm) | tor 0.2.2.34-1 (bookworm) |
| tor | tor | <= 0.2.2.33 | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8686-9px5-f96f: Tor before 0
ghsa_unreviewed·2022-05-17
CVE-2011-2769 [MEDIUM] CWE-200 GHSA-8686-9px5-f96f: Tor before 0
Tor before 0.2.2.34, when configured as a bridge, accepts the CREATE and CREATE_FAST values in the Command field of a cell within an OR connection that it initiated, which allows remote relays to enumerate bridges by using these values.
OSV
CVE-2011-2769: Tor before 0
osv·2011-12-23·CVSS 4.3
CVE-2011-2769 [MEDIUM] CVE-2011-2769: Tor before 0
Tor before 0.2.2.34, when configured as a bridge, accepts the CREATE and CREATE_FAST values in the Command field of a cell within an OR connection that it initiated, which allows remote relays to enumerate bridges by using these values.
Debian
CVE-2011-2769: tor - Tor before 0.2.2.34, when configured as a bridge, accepts the CREATE and CREATE_...
vendor_debian·2011·CVSS 4.3
CVE-2011-2769 [MEDIUM] CVE-2011-2769: tor - Tor before 0.2.2.34, when configured as a bridge, accepts the CREATE and CREATE_...
Tor before 0.2.2.34, when configured as a bridge, accepts the CREATE and CREATE_FAST values in the Command field of a cell within an OR connection that it initiated, which allows remote relays to enumerate bridges by using these values.
Scope: local
bookworm: resolved (fixed in 0.2.2.34-1)
bullseye: resolved (fixed in 0.2.2.34-1)
forky: resolved (fixed in 0.2.2.34-1)
sid: resolved (fixed in 0.2.2.34-1)
trixie: resolved (fixed in 0.2.2.34-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2768 CVE-2011-2769 tor: multiple flaws corrected in 0.2.2.34 [epel-5]
bugzilla·2011-10-28·CVSS 5.8
CVE-2011-2768 [MEDIUM] CVE-2011-2768 CVE-2011-2769 tor: multiple flaws corrected in 0.2.2.34 [epel-5]
CVE-2011-2768 CVE-2011-2769 tor: multiple flaws corrected in 0.2.2.34 [epel-5]
epel-5 tracking bug for tor: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
all updated long time ago
Bugzilla
CVE-2011-2768 CVE-2011-2769 tor: multiple flaws corrected in 0.2.2.34 [fedora-all]
bugzilla·2011-10-28·CVSS 5.8
CVE-2011-2768 [MEDIUM] CVE-2011-2768 CVE-2011-2769 tor: multiple flaws corrected in 0.2.2.34 [fedora-all]
CVE-2011-2768 CVE-2011-2769 tor: multiple flaws corrected in 0.2.2.34 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=s
Bugzilla
CVE-2011-2768 CVE-2011-2769 tor: multiple flaws corrected in 0.2.2.34
bugzilla·2011-10-28·CVSS 5.8
CVE-2011-2768 [MEDIUM] CVE-2011-2768 CVE-2011-2769 tor: multiple flaws corrected in 0.2.2.34
CVE-2011-2768 CVE-2011-2769 tor: multiple flaws corrected in 0.2.2.34
The Tor project has released 0.2.2.34 [1] which corrects the following flaws:
A design flaw in Tor could allow a malicious relay server to learn certain information that they should not be able to learn. A malicious relay that a user connected to directly could learn which other relays that user is connected to directly. Combining this with other attacks, this flaw could lead to de-anonymizing the user (CVE-2011-2768). [2],[3],[4]
In 0.2.2.34, bridges now refuse CREATE or CREATE_FAST cells on OR connections that they initiated. Previously, relays could distinguish incoming bridge connections from client connections, creating another avenue for enumerating bridges (CVE-2011-2769). [5]
[1] https://blog.torproject.org/b
2011-12-23
Published