2.1
CVE-2011-0016
- EPSS 0.4%
- Veröffentlicht 19.01.2011 12:00:19
- Zuletzt bearbeitet 16.06.2026 23:26:37
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly manage key data in memory, which might allow local users to obtain sensitive information by leveraging the ability to read memory that was previously used by a different process.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.317 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
http://archives.seul.org/or/announce/Jan-2011/msg00000.html
http://blog.torproject.org/blog/tor-02129-released-security-patches
http://secunia.com/advisories/42905
http://secunia.com/advisories/42907
http://www.debian.org/security/2011/dsa-2148
http://www.openwall.com/lists/oss-security/2011/01/18/7
http://www.securityfocus.com/bid/45832
http://www.securitytracker.com/id?1024980
http://www.vupen.com/english/advisories/2011/0131
http://www.vupen.com/english/advisories/2011/0132
https://gitweb.torproject.org/tor.git/blob/refs/heads/release-0.2.2:/ChangeLog
https://trac.torproject.org/projects/tor/ticket/2384
https://trac.torproject.org/projects/tor/ticket/2385