Debian Tor vulnerabilities
89 known vulnerabilities affecting debian/tor.
Total CVEs
89
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH26MEDIUM42LOW17
Vulnerabilities
Page 3 of 5
CVE-2006-3407P4MEDIUMCVSS 6.4fixed in tor 0.1.1.20-1 (bookworm)2006
CVE-2006-3407 [MEDIUM] CVE-2006-3407: tor - Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly exe...
Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.
Scope: local
bookworm: resolved (fixed in 0.1.1.20-1)
bullseye: resolved (fixed in 0.1.1.20-1)
forky: resolved (fixed in 0.1.1.20-1)
sid: resolved (fixed in 0.1.1.20-1)
trixie: resolved (fixed in 0.1.1.20-1)
debian
CVE-2011-0015P4MEDIUMCVSS 5.0fixed in tor 0.2.1.29-1 (bookworm)2011
CVE-2011-0015 [MEDIUM] CVE-2011-0015: tor - Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check th...
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allows remote attackers to cause a denial of service via a large compression factor.
Scope: local
bookworm: resolved (fixed in 0.2.1.29-1)
bullseye: resolved (fixed in 0.2.1.29-1)
forky: resolved (fixed in 0.2.1.29-1)
sid: resolved (fixe
debian
CVE-2006-3415P4MEDIUMCVSS 6.4fixed in tor 0.1.1.20-1 (bookworm)2006
CVE-2006-3415 [MEDIUM] CVE-2006-3415: tor - Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which ...
Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM) attack via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.1.1.20-1)
bullseye: resolved (fixed in 0.1.1.20-1)
forky: resolved (fixed in 0.1.1.20-1)
sid: resolved (fixed in 0.1.1.20-1)
trixie: resolved (fixed in 0.
debian
CVE-2011-2768P4MEDIUMCVSS 5.8fixed in tor 0.2.2.34-1 (bookworm)2011
CVE-2011-2768 [MEDIUM] CVE-2011-2768: tor - Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certific...
Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows remote relays to bypass intended anonymity properties by reading this chain and then determining the set of entry guards that the client or bridge had selected.
Scope: local
bookworm: resolved (fixed in 0.2.2.34-1)
bullseye: resolv
debian
CVE-2012-5573P4LOWCVSS 5.0fixed in tor 0.2.3.25-1 (bookworm)2012
CVE-2012-5573 [MEDIUM] CVE-2012-5573: tor - The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2....
The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption or excessive cell reception rate) or bypass intended flow-control restrictions via a RELAY_COMMAND_SENDME command.
Scope: local
bookworm: res
debian
CVE-2005-2050P4MEDIUMCVSS 5.0fixed in tor 0.0.9.10-1 (bookworm)2005
CVE-2005-2050 [MEDIUM] CVE-2005-2050: tor - Unknown vulnerability in Tor before 0.1.0.10 allows remote attackers to read arb...
Unknown vulnerability in Tor before 0.1.0.10 allows remote attackers to read arbitrary memory and possibly key information from the exit server's process space.
Scope: local
bookworm: resolved (fixed in 0.0.9.10-1)
bullseye: resolved (fixed in 0.0.9.10-1)
forky: resolved (fixed in 0.0.9.10-1)
sid: resolved (fixed in 0.0.9.10-1)
trixie: resolved (fixed in 0.0.9.10-1)
debian
CVE-2007-4096P4MEDIUMCVSS 5.8fixed in tor 0.1.2.15-1 (bookworm)2007
CVE-2007-4096 [MEDIUM] CVE-2007-4096: tor - Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remo...
Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.1.2.15-1)
bullseye: resolved (fixed in 0.1.2.15-1)
forky: resolved (fixed in 0.1.2.15-1)
sid: resolved (fixed in 0.1.2.15-1)
trixie: resolved (fixed in 0.1.2.15-1)
debian
CVE-2011-1924P4MEDIUMCVSS 5.0fixed in tor 0.2.1.30-1 (bookworm)2011
CVE-2011-1924 [MEDIUM] CVE-2011-1924: tor - Buffer overflow in the policy_summarize function in or/policies.c in Tor before ...
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory authority crash) via a crafted policy that triggers creation of a long port list.
Scope: local
bookworm: resolved (fixed in 0.2.1.30-1)
bullseye: resolved (fixed in 0.2.1.30-1)
forky: resolved (fixed in 0.2.1.30-1)
sid:
debian
CVE-2012-3518P4LOWCVSS 5.0fixed in tor 0.2.3.20-rc-1 (bookworm)2012
CVE-2012-3518 [MEDIUM] CVE-2012-3518: tor - The networkstatus_parse_vote_from_string function in routerparse.c in Tor before...
The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, which allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted (1) vote document or (2) consensus document.
Scope: local
bookworm: resolved (fixed in 0.2.3.20-rc-1)
bullseye: resolved (
debian
CVE-2006-3414P4MEDIUMCVSS 5.0fixed in tor 0.1.1.20-1 (bookworm)2006
CVE-2006-3414 [MEDIUM] CVE-2006-3414: tor - Tor before 0.1.1.20 supports server descriptors that contain hostnames instead o...
Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group users by providing preferential address resolution.
Scope: local
bookworm: resolved (fixed in 0.1.1.20-1)
bullseye: resolved (fixed in 0.1.1.20-1)
forky: resolved (fixed in 0.1.1.20-1)
sid: resolved (fixed in 0.1.1.20-1)
trix
debian
CVE-2013-7295P4LOWCVSS 4.0fixed in tor 0.2.4.20-1 (bookworm)2013
CVE-2013-7295 [MEDIUM] CVE-2013-7295: tor - Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain Hard...
Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge platforms, does not properly generate random numbers for (1) relay identity keys and (2) hidden-service identity keys, which might make it easier for remote attackers to bypass cryptographic protection mechanisms via unspecified vectors.
debian
CVE-2007-4099P4MEDIUMCVSS 5.8fixed in tor 0.1.2.15-1 (bookworm)2007
CVE-2007-4099 [MEDIUM] CVE-2007-4099: tor - Tor before 0.1.2.15 can select a guard node beyond the first listed never-before...
Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with control of certain guard nodes to obtain sensitive information and possibly leverage further attacks.
Scope: local
bookworm: resolved (fixed in 0.1.2.15-1)
bullseye: resolved (fixed in 0.1.2.15-1)
forky: resolved (fixed in 0.1.2.15
debian
CVE-2006-0414P4MEDIUMCVSS 5.0fixed in tor 0.1.1.11-alpha-1 (bookworm)2006
CVE-2006-0414 [MEDIUM] CVE-2006-0414: tor - Tor before 0.1.1.20 allows remote attackers to identify hidden services via a ma...
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.
Scope: local
bookworm: resolved (fixed in 0.1.1.11-alpha-1)
bullseye: resolved (fixed in 0.1.1.11-alpha-1)
forky: resolved (fixed in
debian
CVE-2012-4922P4MEDIUMCVSS 5.0fixed in tor 0.2.3.22-rc-1 (bookworm)2012
CVE-2012-4922 [MEDIUM] CVE-2012-4922: tor - The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x bef...
The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed directory object, a different vulnerability than CVE-2012-4419.
Scope: local
bookworm: resolved (fixed in 0.2.3.22-rc-1)
bul
debian
CVE-2012-4419P4MEDIUMCVSS 5.0fixed in tor 0.2.3.22-rc-1 (bookworm)2012
CVE-2012-4419 [MEDIUM] CVE-2012-4419: tor - The compare_tor_addr_to_addr_policy function in or/policies.c in Tor before 0.2....
The compare_tor_addr_to_addr_policy function in or/policies.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.21-rc, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a zero-valued port field that is not properly handled during policy comparison.
Scope: local
bookworm: resolved (fixed in 0.2.3.22-rc-1)
bullseye: resolved (fixe
debian
CVE-2006-3418P4MEDIUMCVSS 5.0fixed in tor 0.1.1.20-1 (bookworm)2006
CVE-2006-3418 [MEDIUM] CVE-2006-3418: tor - Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint lin...
Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by users or other applications.
Scope: local
bookworm: resolved (fixed in 0.1.1.20-1)
bullseye: resolved (fixed in 0.1.1.20-1)
forky: resolved (fixed in 0.1.1.20-1)
sid: resolved (
debian
CVE-2010-0383P4MEDIUMCVSS 5.0fixed in tor 0.2.1.22-1 (bookworm)2010
CVE-2010-0383 [MEDIUM] CVE-2010-0383: tor - Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity ...
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man-in-the-middle attackers to compromise the anonymity of traffic sources and destinations.
Scope: local
bookworm: resolved (fixed in 0.2.1.22-1)
bullseye: resolved (fixed in 0.2.1.22-1)
forky: resolved (fixed in 0.2.1.22-1)
debian
CVE-2006-3411P4MEDIUMCVSS 6.4fixed in tor 0.1.1.20-1 (bookworm)2006
CVE-2006-3411 [MEDIUM] CVE-2006-3411: tor - TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS ...
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.
Scope: local
bookworm: resolved (fixed in 0.1.1.20-1)
bullseye: resolved (fixed in 0.1.1.20-1)
forky: resolved (fixed in 0.1.1.20-1)
sid: resolved (fixed in 0
debian
CVE-2012-3517P4LOWCVSS 5.0fixed in tor 0.2.3.20-rc-1 (bookworm)2012
CVE-2012-3517 [MEDIUM] CVE-2012-3517: tor - Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote ...
Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors related to failed DNS requests.
Scope: local
bookworm: resolved (fixed in 0.2.3.20-rc-1)
bullseye: resolved (fixed in 0.2.3.20-rc-1)
forky: resolved (fixed in 0.2.3.20-rc-1)
sid: resolved (fixed in 0.2.3.20-rc-1)
trixie: resol
debian
CVE-2010-0385P4LOWCVSS 5.0fixed in tor 0.2.1.22-1 (bookworm)2010
CVE-2010-0385 [MEDIUM] CVE-2010-0385: tor - Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bri...
Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive information about bridge identities and bridge descriptors via a dbg-stability.txt directory query.
Scope: local
bookworm: resolved (fixed in 0.2.1.22-1)
bullseye: resolved (fixed in 0.2.1.22-1)
forky: resolved (fixed in 0.
debian