CVE-2012-3519: Infoleak
Published Aug 26, 2012
·Updated
routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow remote attackers to obtain sensitive information about relay selection via a timing side-channel attack.
Affected Software
1 affected component
Tor (The Onion Router)<=0.2.2.37
Event History
Aug 26, 2012
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3519?
CVE-2012-3519 is considered to have a medium severity due to the potential for remote attackers to exploit timing side-channel attacks.
2
How do I fix CVE-2012-3519?
To fix CVE-2012-3519, upgrade Tor to version 0.2.2.38 or later.
3
What are the consequences of exploiting CVE-2012-3519?
Exploiting CVE-2012-3519 may allow attackers to gain sensitive information about relay selection in the Tor network.
4
Which versions of Tor are affected by CVE-2012-3519?
CVE-2012-3519 affects Tor versions up to and including 0.2.2.37.
5
Can CVE-2012-3519 be mitigated?
Mitigation for CVE-2012-3519 is primarily achieved through upgrading to a patched version of Tor.