CVE-2017-16639: Infoleak
Published Sep 14, 2018
·Updated
Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client IP address, a different vulnerability than CVE-2017-16541. User interaction is required to trigger this vulnerability.
Affected Software
2 affected components
torproject Tor Browser<8.0
Microsoft Windows
Event History
Sep 14, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2017-16639.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature.'
3
How does this vulnerability affect Tor Browser on Windows?
This vulnerability allows remote attackers to bypass the intended anonymity feature of Tor Browser on Windows.
4
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium (4.3).
5
Is user interaction required to trigger this vulnerability?
Yes, user interaction is required to trigger this vulnerability.