CVE Vulnerabilities

CVE-2007-4098

Published: Jul 30, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Tor before 0.1.2.15 does not properly distinguish streamids from different exits, which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.

Affected Software

NameVendorStart VersionEnd Version
TorTor0.1.0.10 (including)0.1.0.10 (including)
TorTor0.1.0.11 (including)0.1.0.11 (including)
TorTor0.1.0.12 (including)0.1.0.12 (including)
TorTor0.1.0.13 (including)0.1.0.13 (including)
TorTor0.1.0.14 (including)0.1.0.14 (including)
TorTor0.1.0.18 (including)0.1.0.18 (including)
TorTor0.1.1.1_alpha (including)0.1.1.1_alpha (including)
TorTor0.1.1.2_alpha (including)0.1.1.2_alpha (including)
TorTor0.1.1.3_alpha (including)0.1.1.3_alpha (including)
TorTor0.1.1.4_alpha (including)0.1.1.4_alpha (including)
TorTor0.1.1.5_alpha (including)0.1.1.5_alpha (including)
TorTor0.1.1.20 (including)0.1.1.20 (including)
TorTor0.1.1.23 (including)0.1.1.23 (including)
TorTor0.1.2.1_alpha-cvs (including)0.1.2.1_alpha-cvs (including)
TorTor0.1.2.14 (including)0.1.2.14 (including)
TorUbuntudapper*
TorUbuntuedgy*
TorUbuntufeisty*
TorUbuntugutsy*
TorUbuntuhardy*
TorUbuntuintrepid*
TorUbuntuupstream*

References