Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8822

Опубликовано: 03 дек. 2017
Источник: debian
EPSS Низкий

Описание

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
torfixed0.3.1.9-1package
torend-of-lifewheezypackage

Примечания

  • https://bugs.torproject.org/21534

  • https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516

EPSS

Процентиль: 53%
0.00304
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 8 лет назад

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.

CVSS3: 3.7
nvd
около 8 лет назад

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.

CVSS3: 3.7
github
больше 3 лет назад

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.

EPSS

Процентиль: 53%
0.00304
Низкий