CVE-2017-8822: Medium severity tor browser vulnerability
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.
Affected Software
Event History
Frequently Asked Questions
What versions of Tor are impacted by CVE-2017-8822?
CVE-2017-8822 affects Tor versions before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9.
What are the implications of CVE-2017-8822?
The vulnerability can lead to a degradation of anonymity by allowing relays with incompletely downloaded descriptors to select themselves in a circuit path.
How can I mitigate the risks associated with CVE-2017-8822?
To mitigate the risks of CVE-2017-8822, update to a fixed version of Tor, such as 0.3.5.16-1 or later.
Is CVE-2017-8822 a critical vulnerability?
CVE-2017-8822 is considered significant because it compromises user anonymity in the Tor network.
What should I do if I am running an affected version of Tor related to CVE-2017-8822?
If you are running an affected version of Tor, immediately upgrade to a patched version to ensure your anonymity is not compromised.