CVE Vulnerabilities

CVE-2017-8822

Published: Dec 03, 2017 | Modified: Nov 21, 2024
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.

Affected Software

Name Vendor Start Version End Version
Tor Tor_project * 0.2.5.16 (excluding)
Tor Tor_project 0.2.6 (including) 0.2.8.17 (excluding)
Tor Tor_project 0.2.9 (including) 0.2.9.14 (excluding)
Tor Tor_project 0.3.0 (including) 0.3.0.13 (excluding)
Tor Tor_project 0.3.1 (including) 0.3.1.9 (excluding)
Tor Ubuntu artful *
Tor Ubuntu trusty *
Tor Ubuntu upstream *
Tor Ubuntu xenial *
Tor Ubuntu zesty *

References