Описание
Tor path lengths too short when "full Vanguards" configured
In Tor Arti before 1.2.3, circuits sometimes incorrectly have a length of 3 (with full vanguards), aka TROVE-2024-004.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2024-35313
- https://gitlab.torproject.org/tpo/core/arti/-/blob/main/CHANGELOG.md#arti-123-15-may-2024
- https://gitlab.torproject.org/tpo/core/arti/-/commit/1a89d5c9659d799a84dd3ff00fae530f5c8ba280
- https://gitlab.torproject.org/tpo/core/arti/-/issues/1400
- https://gitlab.torproject.org/tpo/core/arti/-/issues/1409
- https://gitlab.torproject.org/tpo/core/team/-/wikis/NetworkTeam/TROVE
- https://rustsec.org/advisories/RUSTSEC-2024-0339.html
- https://rustsec.org/advisories/RUSTSEC-2024-0340.html
Пакеты
Наименование
tor-circmgr
rust
Затронутые версииВерсия исправления
= 0.18.0
0.18.1
Наименование
arti
rust
Затронутые версииВерсия исправления
= 1.2.2
1.2.3
Связанные уязвимости
CVSS3: 7.3
nvd
больше 1 года назад
In Tor Arti before 1.2.3, circuits sometimes incorrectly have a length of 3 (with full vanguards), aka TROVE-2024-004.