5.8
CVE-2011-2768
- EPSS 0.77%
- Veröffentlicht 23.12.2011 03:59:21
- Zuletzt bearbeitet 16.06.2026 23:31:57
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows remote relays to bypass intended anonymity properties by reading this chain and then determining the set of entry guards that the client or bridge had selected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.77% | 0.506 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
http://www.debian.org/security/2011/dsa-2331
https://blog.torproject.org/blog/tor-02234-released-security-patches