Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xjm4-pmg6-w3h9

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by users or other applications.

Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by users or other applications.

EPSS

Процентиль: 64%
0.00477
Низкий

Связанные уязвимости

ubuntu
около 19 лет назад

Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by users or other applications.

nvd
около 19 лет назад

Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by users or other applications.

debian
около 19 лет назад

Tor before 0.1.1.20 does not validate that a server descriptor's finge ...

EPSS

Процентиль: 64%
0.00477
Низкий