CVE-2007-4174: Medium severity Tor (The Onion Router) vulnerability
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4174?
CVE-2007-4174 is considered a critical vulnerability that can lead to configuration tampering and loss of anonymity.
How do I fix CVE-2007-4174?
To fix CVE-2007-4174, upgrade your Tor installation to version 0.1.2.16 or later, where the vulnerability is addressed.
What impact does CVE-2007-4174 have on my system?
CVE-2007-4174 may allow remote attackers to modify the torrc configuration file, compromising the anonymity and security of the Tor network.
Which versions of Tor are affected by CVE-2007-4174?
CVE-2007-4174 affects all versions of Tor prior to 0.1.2.16, including several alpha and beta versions.
Is there any workaround for CVE-2007-4174?
There are no effective workarounds for CVE-2007-4174 other than updating to a secure version of Tor.