CVE-2014-5117: Medium severity tor project tor vulnerability
Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an inbound RELAYEARLY cell is received by a client, which makes it easier for remote attackers to conduct traffic-confirmation attacks by using the pattern of RELAY and RELAYEARLY cells as a means of communicating information about hidden service names.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5117?
CVE-2014-5117 has a medium severity rating due to its potential to facilitate traffic-confirmation attacks.
How do I fix CVE-2014-5117?
To fix CVE-2014-5117, upgrade to Tor versions 0.2.5.6-alpha or 0.2.4.23 or later.
What types of systems are affected by CVE-2014-5117?
CVE-2014-5117 affects various versions of the Tor software prior to updates that address the vulnerability.
What is CVE-2014-5117 related to?
CVE-2014-5117 is related to the improper handling of RELAY_EARLY cells, which can aid in traffic analysis.
Is there a workaround for CVE-2014-5117?
There are no known workarounds for CVE-2014-5117 other than updating to the fixed versions.