CVE-2017-8822
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation…
Does this matter?
Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.
Description
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.
- CVSS 3.0
- 3.7 LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-417
- Affected
- tor project/tor · debian/debian linux
- Source
- security@debian.org
References
- https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516Vendor Advisory
- https://bugs.torproject.org/21534Issue Tracking, Vendor Advisory
- https://bugs.torproject.org/24333Vendor Advisory
- https://www.debian.org/security/2017/dsa-4054Third Party Advisory
- https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516Vendor Advisory
- https://bugs.torproject.org/21534Issue Tracking, Vendor Advisory
- https://bugs.torproject.org/24333Vendor Advisory
- https://www.debian.org/security/2017/dsa-4054Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.