CVE-2006-0414: Medium severity Tor (The Onion Router) vulnerability
Tor before 0.1.1.20 allows remote attackers to identify hidden services via a malicious Tor server that attempts a large number of accesses of the hidden service, which eventually causes a circuit to be built through the malicious server.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0414?
CVE-2006-0414 is considered a medium severity vulnerability that allows attackers to identify hidden services.
How do I fix CVE-2006-0414?
To fix CVE-2006-0414, upgrade your Tor software to version 0.1.1.20 or later.
What versions are affected by CVE-2006-0414?
CVE-2006-0414 affects Tor versions prior to 0.1.1.20 including multiple pre-release versions.
What is the impact of CVE-2006-0414?
The impact of CVE-2006-0414 is that it allows remote attackers to build circuits through a malicious server, potentially exposing hidden services.
Is CVE-2006-0414 exploitable remotely?
Yes, CVE-2006-0414 can be exploited remotely by attackers to expose hidden services via malicious Tor servers.