CVE-2006-3411: Medium severity tor (the onion router) vulnerability
TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3411?
CVE-2006-3411 is considered a medium severity vulnerability due to its potential for facilitating brute force attacks on private keys.
How do I fix CVE-2006-3411?
To fix CVE-2006-3411, upgrade to Tor version 0.1.1.20 or later, which addresses the key generation issue.
Which versions of Tor are affected by CVE-2006-3411?
CVE-2006-3411 affects all versions of Tor prior to 0.1.1.20, including various pre-release versions.
What kind of attack can exploit CVE-2006-3411?
CVE-2006-3411 can be exploited by remote attackers through brute force attacks aimed at the generated encryption keys.
Is CVE-2006-3411 a client-side or server-side vulnerability?
CVE-2006-3411 is considered a server-side vulnerability as it affects the key generation process used by Tor.