Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man-in-the-middle attackers to compromise the anonymity of traffic sources and destinations.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/37901 | vdb entry |
http://osvdb.org/61977 | vdb entry |
http://archives.seul.org/or/announce/Jan-2010/msg00000.html | mailing list |
http://secunia.com/advisories/38198 | third party advisory vendor advisory |
http://archives.seul.org/or/talk/Jan-2010/msg00161.html | mailing list |
http://archives.seul.org/or/talk/Jan-2010/msg00165.html | mailing list |
http://archives.seul.org/or/talk/Jan-2010/msg00162.html | mailing list |