CVE-2007-4174
Summary
| CVE | CVE-2007-4174 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-08-07 10:17:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Tor | Tor | 0.1.2.1 | alpha | All | All |
| Application | Tor | Tor | 0.1.2.10 | All | All | All |
| Application | Tor | Tor | 0.1.2.11 | All | All | All |
| Application | Tor | Tor | 0.1.2.12 | All | All | All |
| Application | Tor | Tor | 0.1.2.13 | All | All | All |
| Application | Tor | Tor | 0.1.2.14 | All | All | All |
| Application | Tor | Tor | 0.1.2.2 | All | All | All |
| Application | Tor | Tor | 0.1.2.3 | alpha | All | All |
| Application | Tor | Tor | 0.1.2.4 | All | All | All |
| Application | Tor | Tor | 0.1.2.5 | All | All | All |
| Application | Tor | Tor | 0.1.2.5 | alpha | All | All |
| Application | Tor | Tor | 0.1.2.6 | alpha | All | All |
| Application | Tor | Tor | 0.1.2.7 | alpha | All | All |
| Application | Tor | Tor | 0.1.2.8 | beta | All | All |
| Application | Tor | Tor | 0.1.2.9 | All | All | All |
| Application | Tor | Tor | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Tor ControlPort Authentication Bug Lets Remote Users Modify the 'torrc' Configuration File - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Tor ControlPort "torrc" Rewrite Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Tor 0.1.2.16 is released | af854a3a-2127-422b-91ae-364da2661108 | archives.seul.org | |
| Tor ControlPort Missing Authentication Unauthorized Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| osvdb.org/36271 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Tor security advisory: cross-protocol http form attack | af854a3a-2127-422b-91ae-364da2661108 | archives.seul.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.