CVE-2021-39246
Summary
| CVE | CVE-2021-39246 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-24 19:15:00 UTC |
| Updated | 2021-10-01 13:00:00 UTC |
| Description | Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact timestamps of these onion-service visits are logged locally, and an attacker might be able to compare them to timestamp data collected by the destination server (or collected by a rogue site within the Tor network). |
Risk And Classification
Problem Types: CWE-532
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Macos | - | All | All | All |
| Operating System | Linux | Linux Kernel | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Torproject | Tor Browser | 11.0 | alpha2 | All | All |
| Application | Torproject | Tor Browser | 11.0 | alpha4 | All | All |
| Application | Torproject | Tor Browser | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Update connection_edge.c (!434) · Merge requests · The Tor Project / Core / Tor · GitLab | MISC | gitlab.torproject.org | |
| TOR Vulnerability Allows Attackers to View Exact Timestamp a User Connected to a v2 Onion Address - Privacy Affairs | MISC | www.privacyaffairs.com | |
| security/SICK-2021-111.md at master · sickcodes/security · GitHub | MISC | github.com | |
| CVE-2021-39246 - Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack excessive verbose logging - Windows, macOS, Linux - Sick Codes - Security Research, Hardware & Software Hacking, Consulting, Linux, IoT, Cloud, Embedded, Arch, Tweaks & Tips! | MISC | sick.codes | |
| Log warning when connecting to soon-to-be-deprecated v2 onions. (80c404c4) · Commits · The Tor Project / Core / Tor · GitLab | MISC | gitlab.torproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.