Vulnerability CVE-2017-8822: Information
Description
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.
Severity: LOW (3.7) Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
tor | sisyphus | 0.3.1.9-alt1.S1 | 0.4.8.6-alt1 | ALT-PU-2017-2718-1 | 195681 | Fixed |
tor | p10 | 0.3.1.9-alt1.S1 | 0.4.8.6-alt1 | ALT-PU-2017-2718-1 | 195681 | Fixed |
tor | p9 | 0.3.1.9-alt1.S1 | 0.4.3.6-alt1 | ALT-PU-2017-2718-1 | 195681 | Fixed |
tor | p8 | 0.3.1.9-alt1.M80P.1 | 0.3.1.9-alt1.M80P.1 | ALT-PU-2017-2750-1 | 195838 | Fixed |
tor | c10f2 | 0.3.1.9-alt1.S1 | 0.4.7.13-alt1 | ALT-PU-2017-2718-1 | 195681 | Fixed |
tor | c9f2 | 0.3.1.9-alt1.S1 | 0.4.3.6-alt1 | ALT-PU-2017-2718-1 | 195681 | Fixed |
tor | p11 | 0.3.1.9-alt1.S1 | 0.4.8.6-alt1 | ALT-PU-2017-2718-1 | 195681 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516 |
|
https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516 |
|
https://bugs.torproject.org/21534 |
|
https://bugs.torproject.org/21534 |
|
https://bugs.torproject.org/24333 |
|
https://bugs.torproject.org/24333 |
|
DSA-4054 |
|
DSA-4054 |
|