Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0.
Link | Tags |
---|---|
http://secunia.com/advisories/34583 | third party advisory |
http://archives.seul.org/or/announce/Feb-2009/msg00000.html | mailing list |
http://secunia.com/advisories/33880 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/33713 | vdb entry |
http://security.gentoo.org/glsa/glsa-200904-11.xml | vendor advisory |