[Bug 230927] New: CVE-2007-1103: tor information disclosure | |
| [Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] | |
Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug report.
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230927
Summary: CVE-2007-1103: tor information disclosure
Product: Fedora Extras
Version: fc6
Platform: All
OS/Version: Linux
Status: NEW
Severity: low
Priority: medium
Component: tor
AssignedTo: enrico.scholz@xxxxxxxxxxxxxxxxxxxxxxxxx
ReportedBy: ville.skytta@xxxxxx
QAContact: extras-qa@xxxxxxxxxxxxxxxxx
CC: fedora-security-list@xxxxxxxxxx
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1103
"Tor does not verify a node's uptime and bandwidth advertisements, which allows
remote attackers who operate a low resource node to make false claims of greater
resources, which places the node into use for many circuits and compromises the
anonymity of traffic sources and destinations."
All <= 0.1.1.26 versions reportedly affected. Upstream statement:
http://blogs.law.harvard.edu/anonymous/2007/02/26/the-rumors-of-our-demise/
--
Configure bugmail: https://bugzilla.redhat.com/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug, or are watching someone who is.
--
Fedora-security-list mailing list
Fedora-security-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-security-list
[Home] [Fedora Legacy List] [Fedora Maintainers] [Fedora Desktop] [Red Hat 9 Bible] [Fedora Bible] [Fedora SELinux] [Big List of Linux Books] [Yosemite News] [Yosemite Photos] [KDE Users] [Coolkey] [Fedora Tools]