CVE-2007-1103

Tor does not verify a node's uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of traffic sources and destinations.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tor:tor:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:27

Type Values Removed Values Added
References () http://archives.seul.org/or/talk/Feb-2007/msg00197.html - () http://archives.seul.org/or/talk/Feb-2007/msg00197.html -
References () http://archives.seul.org/or/talk/Feb-2007/msg00200.html - () http://archives.seul.org/or/talk/Feb-2007/msg00200.html -
References () http://archives.seul.org/or/talk/Feb-2007/msg00202.html - () http://archives.seul.org/or/talk/Feb-2007/msg00202.html -
References () http://osvdb.org/45249 - () http://osvdb.org/45249 -
References () http://www.cs.colorado.edu/department/publications/reports/docs/CU-CS-1025-07.pdf - () http://www.cs.colorado.edu/department/publications/reports/docs/CU-CS-1025-07.pdf -

Information

Published : 2007-02-26 17:28

Updated : 2024-11-21 00:27


NVD link : CVE-2007-1103

Mitre link : CVE-2007-1103

CVE.ORG link : CVE-2007-1103


JSON object : View

Products Affected

tor

  • tor