VulnerabilityModified
CVE-2007-3165
Tor before 0.1.2.14 can construct circuits in which an entry guard is in the same family as the exit node, which might compromise the anonymity of traffic sources and destinations by exposing traffic to inappropriate remote observers.
MEDIUM 5.0EPSS 1.48%
Does this matter?
Lower severity and a low EPSS score (1.48%). Track it; it rarely justifies an emergency change on its own.
Description
Tor before 0.1.2.14 can construct circuits in which an entry guard is in the same family as the exit node, which might compromise the anonymity of traffic sources and destinations by exposing traffic to inappropriate remote observers.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.48% probability · 72th percentile
- CISA KEV
- Not listed
- Affected
- tor/tor
- Source
- cve@mitre.org
References
- http://archives.seul.org/or/announce/May-2007/msg00000.html
- http://osvdb.org/35670
- http://secunia.com/advisories/25415Patch, Vendor Advisory
- http://www.securityfocus.com/bid/24180Patch
- http://www.vupen.com/english/advisories/2007/1964
- http://archives.seul.org/or/announce/May-2007/msg00000.html
- http://osvdb.org/35670
- http://secunia.com/advisories/25415Patch, Vendor Advisory
- http://www.securityfocus.com/bid/24180Patch
- http://www.vupen.com/english/advisories/2007/1964
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.