Tor: Information disclosure
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200508-16 / tor |
| Release Date |
August 25, 2005 |
| Latest Revision |
August 25, 2005: 01 |
| Impact |
low |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-misc/tor |
<
0.1.0.14 |
>=
0.1.0.14 |
All supported architectures
|
Related bugreports:
#102245
Synopsis
A flaw in Tor leads to the disclosure of information and the loss of
anonymity, integrity and confidentiality.
2.
Impact Information
Background
Tor is an implementation of second generation Onion Routing, a
connection-oriented anonymizing communication service.
Description
The Diffie-Hellman implementation of Tor fails to verify the
cryptographic strength of keys which are used during handshakes.
Impact
By setting up a malicious Tor server and enticing users to use
this server as first hop, a remote attacker could read and modify all
traffic of the user.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All Tor users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/tor-0.1.0.14"
|
4.
References
|