CVE-2007-4097: Medium severity Tor (The Onion Router) vulnerability
Published Jul 30, 2007
·Updated
Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitive information, contrary to specifications.
Affected Software
15 affected components
Tor (The Onion Router)=0.1.1.1_alpha
Tor (The Onion Router)=0.1.2.1_alpha-cvs
Tor (The Onion Router)=0.1.0.18
Tor (The Onion Router)=0.1.1.23
Tor (The Onion Router)=0.1.0.10
Tor (The Onion Router)=0.1.0.12
Tor (The Onion Router)=0.1.1.3_alpha
Tor (The Onion Router)=0.1.2.14
Tor (The Onion Router)=0.1.0.13
Tor (The Onion Router)=0.1.0.14
Tor (The Onion Router)=0.1.1.4_alpha
Tor (The Onion Router)=0.1.1.2_alpha
Tor (The Onion Router)=0.1.1.20
Tor (The Onion Router)=0.1.1.5_alpha
Tor (The Onion Router)=0.1.0.11
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jul 30, 2007
CVE Published
09:17 PM
Jul 31, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4097?
CVE-2007-4097 is considered to have a moderate severity level due to the potential information leak.
2
How do I fix CVE-2007-4097?
To fix CVE-2007-4097, upgrade to Tor version 0.1.2.15 or later, which addresses the vulnerability.
3
What versions of Tor are affected by CVE-2007-4097?
CVE-2007-4097 affects Tor versions prior to 0.1.2.15, including various earlier alpha releases.
4
What type of attack is associated with CVE-2007-4097?
CVE-2007-4097 allows remote attackers to perform information disclosure attacks exploiting the circuit teardown mechanism.
5
What is the impact of CVE-2007-4097?
The impact of CVE-2007-4097 includes the potential for remote attackers to obtain sensitive information during circuit destruction.