5.1

CVE-2009-0654

Exploit
Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell, and then observing cell recognition errors at the exit router.  NOTE: the vendor disputes the significance of this issue, noting that the product's design "accepted end-to-end correlation as an attack that is too expensive to solve."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TorTor Updatealpha Version <= 0.2.0.34
TorTor Version0.2.0.1 Updatealpha
TorTor Version0.2.0.2 Updatealpha
TorTor Version0.2.0.3 Updatealpha
TorTor Version0.2.0.4 Updatealpha
TorTor Version0.2.0.5 Updatealpha
TorTor Version0.2.0.6 Updatealpha
TorTor Version0.2.0.7 Updatealpha
TorTor Version0.2.0.8 Updatealpha
TorTor Version0.2.0.9 Updatealpha
TorTor Version0.2.0.10 Updatealpha
TorTor Version0.2.0.11 Updatealpha
TorTor Version0.2.0.12 Updatealpha
TorTor Version0.2.0.13 Updatealpha
TorTor Version0.2.0.14 Updatealpha
TorTor Version0.2.0.15 Updatealpha
TorTor Version0.2.0.16 Updatealpha
TorTor Version0.2.0.17 Updatealpha
TorTor Version0.2.0.18 Updatealpha
TorTor Version0.2.0.19 Updatealpha
TorTor Version0.2.0.20 Updatealpha
TorTor Version0.2.0.21 Updatealpha
TorTor Version0.2.0.22 Updatealpha
TorTor Version0.2.0.23 Updatealpha
TorTor Version0.2.0.24 Updatealpha
TorTor Version0.2.0.25 Updatealpha
TorTor Version0.2.0.26 Updatealpha
TorTor Version0.2.0.27 Updatealpha
TorTor Version0.2.0.28 Updatealpha
TorTor Version0.2.0.29 Updatealpha
TorTor Version0.2.0.30 Updatealpha
TorTor Version0.2.0.31 Updatealpha
TorTor Version0.2.0.32 Updatealpha
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.524
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.