CVE-2006-3412: Medium severity Tor (The Onion Router) vulnerability
Tor before 0.1.1.20 does not sufficiently obey certain firewall options, which allows remote attackers to bypass intended access restrictions for dirservers, direct connections, or proxy servers.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3412?
CVE-2006-3412 is classified as a moderate severity vulnerability due to its potential to allow unauthorized access to directory servers and proxy servers.
How do I fix CVE-2006-3412?
To fix CVE-2006-3412, upgrade to Tor version 0.1.1.20 or later, which addresses the vulnerability.
What types of software are affected by CVE-2006-3412?
CVE-2006-3412 affects various versions of Tor prior to 0.1.1.20 including 0.0.2 through 0.1.1.9_alpha.
What can attackers do using CVE-2006-3412?
Attackers can exploit CVE-2006-3412 to bypass intended access restrictions for directory servers, enabling unauthorized access.
Is CVE-2006-3412 still relevant today?
While CVE-2006-3412 is a historical vulnerability, its implications highlight the importance of timely software updates to mitigate security risks.