CVE-2017-0377: Infoleak
Published Jul 2, 2017
·Updated
Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties by leveraging the existence of large families.
Affected Software
8 affected components
torproject Tor=0.3.0.1-alpha
torproject Tor=0.3.0.2-alpha
torproject Tor=0.3.0.3-alpha
torproject Tor=0.3.0.4
torproject Tor=0.3.0.5
torproject Tor=0.3.0.6
torproject Tor=0.3.0.7
torproject Tor=0.3.0.8
Remediation
Event History
Jul 2, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-0377?
CVE-2017-0377 has a medium severity level as it may compromise anonymity properties in Tor.
2
How do I fix CVE-2017-0377?
To fix CVE-2017-0377, upgrade to Tor version 0.3.0.9 or later.
3
What software is affected by CVE-2017-0377?
CVE-2017-0377 affects Tor versions 0.3.0.1-alpha to 0.3.0.8.
4
What is the impact of CVE-2017-0377?
The impact of CVE-2017-0377 is that it potentially allows remote attackers to defeat the intended anonymity provided by the Tor network.
5
Is there a workaround for CVE-2017-0377?
There is no specific workaround for CVE-2017-0377; users should update to a patched version of Tor.