CVE Vulnerabilities

CVE-2007-4098

Published: Jul 30, 2007 | Modified: Mar 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Tor before 0.1.2.15 does not properly distinguish streamids from different exits, which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.

Affected Software

Name Vendor Start Version End Version
Tor Tor 0.1.0.10 (including) 0.1.0.10 (including)
Tor Tor 0.1.0.11 (including) 0.1.0.11 (including)
Tor Tor 0.1.0.12 (including) 0.1.0.12 (including)
Tor Tor 0.1.0.13 (including) 0.1.0.13 (including)
Tor Tor 0.1.0.14 (including) 0.1.0.14 (including)
Tor Tor 0.1.0.18 (including) 0.1.0.18 (including)
Tor Tor 0.1.1.1_alpha (including) 0.1.1.1_alpha (including)
Tor Tor 0.1.1.2_alpha (including) 0.1.1.2_alpha (including)
Tor Tor 0.1.1.3_alpha (including) 0.1.1.3_alpha (including)
Tor Tor 0.1.1.4_alpha (including) 0.1.1.4_alpha (including)
Tor Tor 0.1.1.5_alpha (including) 0.1.1.5_alpha (including)
Tor Tor 0.1.1.20 (including) 0.1.1.20 (including)
Tor Tor 0.1.1.23 (including) 0.1.1.23 (including)
Tor Tor 0.1.2.1_alpha-cvs (including) 0.1.2.1_alpha-cvs (including)
Tor Tor 0.1.2.14 (including) 0.1.2.14 (including)
Tor Ubuntu dapper *
Tor Ubuntu edgy *
Tor Ubuntu feisty *
Tor Ubuntu gutsy *
Tor Ubuntu hardy *
Tor Ubuntu intrepid *
Tor Ubuntu upstream *

References