[Bug 244502] New: CVE-2007-3165: tor < 0.1.2.14 information disclosure

bugzilla at redhat.com bugzilla at redhat.com
Sat Jun 16 09:25:15 UTC 2007


Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug report.




https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=244502

           Summary: CVE-2007-3165: tor < 0.1.2.14 information disclosure
           Product: Fedora Extras
           Version: f7
          Platform: All
               URL: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-3165
        OS/Version: Linux
            Status: NEW
          Severity: medium
          Priority: medium
         Component: tor
        AssignedTo: enrico.scholz at informatik.tu-chemnitz.de
        ReportedBy: ville.skytta at iki.fi
         QAContact: extras-qa at fedoraproject.org
                CC: fedora-security-list at redhat.com


http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-3165

"Tor before 0.1.2.14 can construct circuits in which an entry guard is in the
same family as the exit node, which might compromise the anonymity of traffic
sources and destinations by exposing traffic to inappropriate remote observers."

-- 
Configure bugmail: https://bugzilla.redhat.com/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug, or are watching someone who is.




More information about the security mailing list