Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-5117


Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an inbound RELAY_EARLY cell is received by a client, which makes it easier for remote attackers to conduct traffic-confirmation attacks by using the pattern of RELAY and RELAY_EARLY cells as a means of communicating information about hidden service names.


Published

2014-07-30T16:55:07.073

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application torproject tor ≤ 0.2.4.22 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.2 Yes
Application torproject tor 0.0.3 Yes
Application torproject tor 0.0.4 Yes
Application torproject tor 0.0.5 Yes
Application torproject tor 0.0.6 Yes
Application torproject tor 0.0.6.1 Yes
Application torproject tor 0.0.6.2 Yes
Application torproject tor 0.0.7 Yes
Application torproject tor 0.0.7.1 Yes
Application torproject tor 0.0.7.2 Yes
Application torproject tor 0.0.7.3 Yes
Application torproject tor 0.0.8.1 Yes
Application torproject tor 0.0.9.1 Yes
Application torproject tor 0.0.9.2 Yes
Application torproject tor 0.0.9.3 Yes
Application torproject tor 0.0.9.4 Yes
Application torproject tor 0.0.9.5 Yes
Application torproject tor 0.0.9.6 Yes
Application torproject tor 0.0.9.7 Yes
Application torproject tor 0.0.9.8 Yes
Application torproject tor 0.0.9.9 Yes
Application torproject tor 0.0.9.10 Yes
Application torproject tor 0.1.0.10 Yes
Application torproject tor 0.1.0.11 Yes
Application torproject tor 0.1.0.12 Yes
Application torproject tor 0.1.0.13 Yes
Application torproject tor 0.1.0.14 Yes
Application torproject tor 0.1.0.15 Yes
Application torproject tor 0.1.0.16 Yes
Application torproject tor 0.1.0.17 Yes
Application torproject tor 0.1.1.20 Yes
Application torproject tor 0.1.1.21 Yes
Application torproject tor 0.1.1.22 Yes
Application torproject tor 0.1.1.23 Yes
Application torproject tor 0.1.1.24 Yes
Application torproject tor 0.1.1.25 Yes
Application torproject tor 0.1.1.26 Yes
Application torproject tor 0.1.2.13 Yes
Application torproject tor 0.1.2.14 Yes
Application torproject tor 0.1.2.15 Yes
Application torproject tor 0.1.2.16 Yes
Application torproject tor 0.1.2.17 Yes
Application torproject tor 0.1.2.18 Yes
Application torproject tor 0.1.2.19 Yes
Application torproject tor 0.2.0.30 Yes
Application torproject tor 0.2.0.31 Yes
Application torproject tor 0.2.0.32 Yes
Application torproject tor 0.2.0.33 Yes
Application torproject tor 0.2.0.34 Yes
Application torproject tor 0.2.0.35 Yes
Application torproject tor 0.2.2.18 Yes
Application torproject tor 0.2.2.19 Yes
Application torproject tor 0.2.2.20 Yes
Application torproject tor 0.2.2.21 Yes
Application torproject tor 0.2.2.22 Yes
Application torproject tor 0.2.2.23 Yes
Application torproject tor 0.2.2.24 Yes
Application torproject tor 0.2.2.25 Yes
Application torproject tor 0.2.2.26 Yes
Application torproject tor 0.2.2.27 Yes
Application torproject tor 0.2.2.28 Yes
Application torproject tor 0.2.2.29 Yes
Application torproject tor 0.2.2.30 Yes
Application torproject tor 0.2.2.31 Yes
Application torproject tor 0.2.2.32 Yes
Application torproject tor 0.2.2.33 Yes
Application torproject tor 0.2.2.34 Yes
Application torproject tor 0.2.2.35 Yes
Application torproject tor 0.2.2.36 Yes
Application torproject tor 0.2.2.37 Yes
Application torproject tor 0.2.2.38 Yes
Application torproject tor 0.2.3 Yes
Application torproject tor 0.2.3.13 Yes
Application torproject tor 0.2.3.14 Yes
Application torproject tor 0.2.3.15 Yes
Application torproject tor 0.2.3.16 Yes
Application torproject tor 0.2.3.17 Yes
Application torproject tor 0.2.3.18 Yes
Application torproject tor 0.2.3.19 Yes
Application torproject tor 0.2.3.20 Yes
Application torproject tor 0.2.3.21 Yes
Application torproject tor 0.2.3.22 Yes
Application torproject tor 0.2.3.23 Yes
Application torproject tor 0.2.3.24 Yes
Application torproject tor 0.2.4.1 Yes
Application torproject tor 0.2.4.2 Yes
Application torproject tor 0.2.4.3 Yes
Application torproject tor 0.2.4.4 Yes
Application torproject tor 0.2.4.5 Yes
Application torproject tor 0.2.4.6 Yes
Application torproject tor 0.2.4.7 Yes
Application torproject tor 0.2.4.8 Yes
Application torproject tor 0.2.4.9 Yes
Application torproject tor 0.2.4.10 Yes
Application torproject tor 0.2.4.11 Yes
Application torproject tor 0.2.4.12 Yes
Application torproject tor 0.2.4.13 Yes
Application torproject tor 0.2.4.14 Yes
Application torproject tor 0.2.4.15 Yes
Application torproject tor 0.2.4.16 Yes
Application torproject tor 0.2.4.17 Yes
Application torproject tor 0.2.4.18 Yes
Application torproject tor 0.2.4.19 Yes
Application torproject tor 0.2.4.20 Yes
Application torproject tor 0.2.5.2 Yes
Application torproject tor 0.2.5.3 Yes
Application torproject tor 0.2.5.4 Yes
Application torproject tor 0.2.5.5 Yes

References