Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell, and then observing cell recognition errors at the exit router. NOTE: the vendor disputes the significance of this issue, noting that the products design accepted end-to-end correlation as an attack that is too expensive to solve.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tor | Tor | * | 0.2.0.34 (including) |
Tor | Tor | 0.2.0.1-alpha (including) | 0.2.0.1-alpha (including) |
Tor | Tor | 0.2.0.2-alpha (including) | 0.2.0.2-alpha (including) |
Tor | Tor | 0.2.0.3-alpha (including) | 0.2.0.3-alpha (including) |
Tor | Tor | 0.2.0.4-alpha (including) | 0.2.0.4-alpha (including) |
Tor | Tor | 0.2.0.5-alpha (including) | 0.2.0.5-alpha (including) |
Tor | Tor | 0.2.0.6-alpha (including) | 0.2.0.6-alpha (including) |
Tor | Tor | 0.2.0.7-alpha (including) | 0.2.0.7-alpha (including) |
Tor | Tor | 0.2.0.8-alpha (including) | 0.2.0.8-alpha (including) |
Tor | Tor | 0.2.0.9-alpha (including) | 0.2.0.9-alpha (including) |
Tor | Tor | 0.2.0.10-alpha (including) | 0.2.0.10-alpha (including) |
Tor | Tor | 0.2.0.11-alpha (including) | 0.2.0.11-alpha (including) |
Tor | Tor | 0.2.0.12-alpha (including) | 0.2.0.12-alpha (including) |
Tor | Tor | 0.2.0.13-alpha (including) | 0.2.0.13-alpha (including) |
Tor | Tor | 0.2.0.14-alpha (including) | 0.2.0.14-alpha (including) |
Tor | Tor | 0.2.0.15-alpha (including) | 0.2.0.15-alpha (including) |
Tor | Tor | 0.2.0.16-alpha (including) | 0.2.0.16-alpha (including) |
Tor | Tor | 0.2.0.17-alpha (including) | 0.2.0.17-alpha (including) |
Tor | Tor | 0.2.0.18-alpha (including) | 0.2.0.18-alpha (including) |
Tor | Tor | 0.2.0.19-alpha (including) | 0.2.0.19-alpha (including) |
Tor | Tor | 0.2.0.20-alpha (including) | 0.2.0.20-alpha (including) |
Tor | Tor | 0.2.0.21-alpha (including) | 0.2.0.21-alpha (including) |
Tor | Tor | 0.2.0.22-alpha (including) | 0.2.0.22-alpha (including) |
Tor | Tor | 0.2.0.23-alpha (including) | 0.2.0.23-alpha (including) |
Tor | Tor | 0.2.0.24-alpha (including) | 0.2.0.24-alpha (including) |
Tor | Tor | 0.2.0.25-alpha (including) | 0.2.0.25-alpha (including) |
Tor | Tor | 0.2.0.26-alpha (including) | 0.2.0.26-alpha (including) |
Tor | Tor | 0.2.0.27-alpha (including) | 0.2.0.27-alpha (including) |
Tor | Tor | 0.2.0.28-alpha (including) | 0.2.0.28-alpha (including) |
Tor | Tor | 0.2.0.29-alpha (including) | 0.2.0.29-alpha (including) |
Tor | Tor | 0.2.0.30-alpha (including) | 0.2.0.30-alpha (including) |
Tor | Tor | 0.2.0.31-alpha (including) | 0.2.0.31-alpha (including) |
Tor | Tor | 0.2.0.32-alpha (including) | 0.2.0.32-alpha (including) |
Tor | Ubuntu | dapper | * |
Tor | Ubuntu | gutsy | * |
Tor | Ubuntu | hardy | * |
Tor | Ubuntu | intrepid | * |