CVE-2007-4098: Medium severity Tor (The Onion Router) vulnerability

Published Jul 30, 2007
·
Updated

Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.

Affected Software

15 affected components
Tor (The Onion Router)=0.1.1.1_alpha
Tor (The Onion Router)=0.1.2.1_alpha-cvs
Tor (The Onion Router)=0.1.0.18
Tor (The Onion Router)=0.1.1.23
Tor (The Onion Router)=0.1.0.10
Tor (The Onion Router)=0.1.0.12
Tor (The Onion Router)=0.1.1.3_alpha
Tor (The Onion Router)=0.1.2.14
Tor (The Onion Router)=0.1.0.13
Tor (The Onion Router)=0.1.0.14
Tor (The Onion Router)=0.1.1.4_alpha
Tor (The Onion Router)=0.1.1.2_alpha
Tor (The Onion Router)=0.1.1.20
Tor (The Onion Router)=0.1.1.5_alpha
Tor (The Onion Router)=0.1.0.11

Event History

Jul 30, 2007
CVE Published
09:17 PM
Jul 31, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2007-4098?

CVE-2007-4098 is classified as a moderate severity vulnerability that can allow remote attackers to compromise data streams in Tor.

2

How do I fix CVE-2007-4098?

To fix CVE-2007-4098, you should upgrade to Tor version 0.1.2.15 or later.

3

Who is affected by CVE-2007-4098?

CVE-2007-4098 affects all users of the Tor software prior to version 0.1.2.15.

4

What is the impact of CVE-2007-4098 on Tor users?

The impact of CVE-2007-4098 allows attackers with control over Tor routers to potentially inject malicious cells into user streams.

5

Can CVE-2007-4098 lead to data leaks?

Yes, CVE-2007-4098 has the potential to lead to data leaks by allowing unauthorized manipulation of Tor streams.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203