Vulnerabilities
Vulnerable Software
Torproject:  >> Tor  >> 0.2.3.22  Security Vulnerabilities
Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge platforms, does not properly generate random numbers for (1) relay identity keys and (2) hidden-service identity keys, which might make it easier for remote attackers to bypass cryptographic protection mechanisms via unspecified vectors.
CVSS Score
4.0
EPSS Score
0.002
Published
2014-01-17
The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption or excessive cell reception rate) or bypass intended flow-control restrictions via a RELAY_COMMAND_SENDME command.
CVSS Score
5.0
EPSS Score
0.01
Published
2013-01-01


Contact Us

Shodan ® - All rights reserved