Tor Arbitrary Memory Information Disclosure Vulnerability
BID:14024
Info
Tor Arbitrary Memory Information Disclosure Vulnerability
| Bugtraq ID: | 14024 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2005 12:00AM |
| Updated: | Jun 21 2005 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
Tor Tor 0.0.9 .9 Tor Tor 0.0.9 .8 Tor Tor 0.0.9 .7 Tor Tor 0.0.9 .6 Tor Tor 0.0.9 .5 Tor Tor 0.0.9 .4 Tor Tor 0.0.9 .3 Tor Tor 0.0.9 .2 Tor Tor 0.0.9 .10 Tor Tor 0.0.9 .1 Tor Tor 0.0.9 Gentoo Linux |
| Not Vulnerable: |
Tor Tor 0.1 .0.10 |
Discussion
Tor Arbitrary Memory Information Disclosure Vulnerability
Tor is prone to an arbitrary memory information disclosure vulnerability.
A remote attacker could exploit this vulnerability to gain sensitive information, possibly private keys.
This issue is reported to affect Tor versions prior to 0.1.0.10.
Tor is prone to an arbitrary memory information disclosure vulnerability.
A remote attacker could exploit this vulnerability to gain sensitive information, possibly private keys.
This issue is reported to affect Tor versions prior to 0.1.0.10.
Exploit / POC
Tor Arbitrary Memory Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Tor Arbitrary Memory Information Disclosure Vulnerability
Solution:
Gentoo Linux has released advisory GLSA 200506-18 addressing this issue.
Gentoo recommends all Tor users should upgrade to the latest available version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/tor-0.0.9.10"
The vendor has addressed this issue in Tor version 0.1.0.10 and later:
Tor Tor 0.0.9 .1
Tor Tor 0.0.9 .4
Tor Tor 0.0.9 .8
Tor Tor 0.0.9 .10
Tor Tor 0.0.9 .3
Tor Tor 0.0.9 .7
Tor Tor 0.0.9 .6
Tor Tor 0.0.9 .2
Tor Tor 0.0.9
Tor Tor 0.0.9 .5
Tor Tor 0.0.9 .9
Solution:
Gentoo Linux has released advisory GLSA 200506-18 addressing this issue.
Gentoo recommends all Tor users should upgrade to the latest available version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/tor-0.0.9.10"
The vendor has addressed this issue in Tor version 0.1.0.10 and later:
Tor Tor 0.0.9 .1
-
Tor Tor-0.1.0.10
http://tor.eff.org/download.html
Tor Tor 0.0.9 .4
-
Tor Tor-0.1.0.10
http://tor.eff.org/download.html
Tor Tor 0.0.9 .8
-
Tor Tor-0.1.0.10
http://tor.eff.org/download.html
Tor Tor 0.0.9 .10
-
Tor Tor-0.1.0.10
http://tor.eff.org/download.html
Tor Tor 0.0.9 .3
-
Tor Tor-0.1.0.10
http://tor.eff.org/download.html
Tor Tor 0.0.9 .7
-
Tor Tor-0.1.0.10
http://tor.eff.org/download.html
Tor Tor 0.0.9 .6
-
Tor Tor-0.1.0.10
http://tor.eff.org/download.html
Tor Tor 0.0.9 .2
-
Tor Tor-0.1.0.10
http://tor.eff.org/download.html
Tor Tor 0.0.9
-
Tor Tor-0.1.0.10
http://tor.eff.org/download.html
Tor Tor 0.0.9 .5
-
Tor Tor-0.1.0.10
http://tor.eff.org/download.html
Tor Tor 0.0.9 .9
-
Tor Tor-0.1.0.10
http://tor.eff.org/download.html
References
Tor Arbitrary Memory Information Disclosure Vulnerability
References:
References:
- Tor Homepage (Tor)
- Tor security advisory: clients will route traffic (Roger Dingledine)