CVE-2020-8516: Medium severity torproject Tor vulnerability
DISPUTED The daemon in Tor through 0.4.1.8 and 0.4.2.x through 0.4.2.6 does not verify that a rendezvous node is known before attempting to connect to it, which might make it easier for remote attackers to discover circuit information. NOTE: The network team of Tor claims this is an intended behavior and not a vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-8516?
CVE-2020-8516 is a vulnerability in the Tor daemon that allows remote attackers to discover circuit information.
What is the severity of CVE-2020-8516?
The severity of CVE-2020-8516 is medium with a CVSS score of 5.3.
How does CVE-2020-8516 affect Tor?
CVE-2020-8516 affects Tor versions 0.4.1.8 and 0.4.2.x through 0.4.2.6.
What is the remedy for CVE-2020-8516?
There is currently no remedy available for CVE-2020-8516. It is advised to update to a patched version when it becomes available.
Where can I find more information about CVE-2020-8516?
You can find more information about CVE-2020-8516 at the following references: [Link 1](https://lists.torproject.org/pipermail/tor-dev/2020-February/014146.html), [Link 2](https://lists.torproject.org/pipermail/tor-dev/2020-February/014147.html), [Link 3](https://security-tracker.debian.org/tracker/CVE-2020-8516).