CVE-2013-7295: Medium severity torproject Tor vulnerability
Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge platforms, does not properly generate random numbers for (1) relay identity keys and (2) hidden-service identity keys, which might make it easier for remote attackers to bypass cryptographic protection mechanisms via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7295?
CVE-2013-7295 has been classified as a moderate severity vulnerability due to its impact on cryptographic key generation.
How do I fix CVE-2013-7295?
To fix CVE-2013-7295, upgrade to Tor version 0.2.4.20 or later.
Which versions of Tor are affected by CVE-2013-7295?
CVE-2013-7295 affects all Tor versions prior to 0.2.4.20, including numerous alpha and release candidate versions.
What platforms are impacted by CVE-2013-7295?
CVE-2013-7295 specifically affects Intel Sandy Bridge and Ivy Bridge platforms when using certain OpenSSL configurations.
What types of keys are vulnerable in CVE-2013-7295?
CVE-2013-7295 affects the generation of relay identity keys and hidden-service identity keys.