CVE-2009-0654: Medium severity Tor (The Onion Router) vulnerability
Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell, and then observing cell recognition errors at the exit router. NOTE: the vendor disputes the significance of this issue, noting that the product's design "accepted end-to-end correlation as an attack that is too expensive to solve."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0654?
CVE-2009-0654 is classified as a medium severity vulnerability that impacts the anonymity of users on the Tor network.
How do I fix CVE-2009-0654?
To mitigate CVE-2009-0654, it is recommended to upgrade to a later version of Tor that addresses this vulnerability.
What versions of Tor are affected by CVE-2009-0654?
CVE-2009-0654 affects Tor versions from 0.2.0.28 down to 0.2.0.1-alpha.
What type of attacks does CVE-2009-0654 enable?
CVE-2009-0654 allows attackers with control of both an entry and exit router to potentially correlate communications.
Is it safe to use Tor versions affected by CVE-2009-0654?
Using affected Tor versions can compromise privacy and anonymity, so it is not recommended.