CVE-2006-3413: Medium severity tor (the onion router) vulnerability
The privoxy configuration file in Tor before 0.1.1.20, when run on Apple OS X, logs all data via the "logfile", which allows attackers to obtain potentially sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3413?
CVE-2006-3413 has a high severity rating due to its potential to expose sensitive information through logging.
How do I fix CVE-2006-3413?
To fix CVE-2006-3413, upgrade to a version of Tor that addresses this vulnerability, specifically versions 0.1.1.20 or later.
Which versions of Tor are affected by CVE-2006-3413?
CVE-2006-3413 affects several Tor versions including 0.1.1.1_alpha, 0.0.6.2, and earlier versions.
What is the impact of CVE-2006-3413?
The impact of CVE-2006-3413 allows attackers to gain access to potentially sensitive information logged by the privoxy configuration.
Can CVE-2006-3413 be exploited remotely?
Yes, CVE-2006-3413 can be exploited remotely by attackers leveraging the logging mechanism to access sensitive data.