CVE-2006-3414: Medium severity Tor (The Onion Router) vulnerability
Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group users by providing preferential address resolution.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3414?
CVE-2006-3414 is classified as a moderate severity vulnerability due to its potential to allow grouping of users by preferential address resolution.
How do I fix CVE-2006-3414?
To fix CVE-2006-3414, update your Tor installation to a version greater than 0.1.1.20.
What impact does CVE-2006-3414 have on Tor users?
CVE-2006-3414 can compromise user anonymity by allowing attackers to organize users based on hostname resolution, potentially leading to targeted attacks.
Which versions of Tor are affected by CVE-2006-3414?
CVE-2006-3414 affects multiple versions of Tor including all versions earlier than 0.1.1.20.
Is there a known exploit for CVE-2006-3414?
While there are no widespread public exploits reported for CVE-2006-3414, the vulnerability itself poses a risk to user privacy and anonymity.