CVE-2011-4895Sensitive Information Exposure in TOR

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 51.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 23
Latest updateMay 17

Description

Tor before 0.2.2.34, when configured as a bridge, sets up circuits through a process different from the process used by a client, which makes it easier for remote attackers to enumerate bridges by observing circuit building.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

Debiantorproject/tor< 0.2.2.34-1+3
NVDtor/tor0.2.2.33+204

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vv8x-qxvx-9wjx: Tor before 02022-05-17
CVEList
CVE-2011-4895: Tor before 02011-12-23
OSV
CVE-2011-4895: Tor before 02011-12-23

📋Vendor Advisories

1
Debian
CVE-2011-4895: tor - Tor before 0.2.2.34, when configured as a bridge, sets up circuits through a pro...2011

💬Community

3
Bugzilla
CVE-2011-4894 CVE-2011-4895 CVE-2011-4896 tor various flaws [fedora-all]2012-01-03
Bugzilla
CVE-2011-4894 CVE-2011-4895 CVE-2011-4896 tor various flaws [epel-all]2012-01-03
Bugzilla
CVE-2011-4895 Tor Bridge circuit building information disclosure2011-12-23
CVE-2011-4895 — Sensitive Information Exposure in TOR | cvebase