Tor before 0.2.2.34, when configured as a bridge, accepts the CREATE and CREATE_FAST values in the Command field of a cell within an OR connection that it initiated, which allows remote relays to enumerate bridges by using these values.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://blog.torproject.org/blog/tor-02234-released-security-patches | patch vendor advisory |
http://www.debian.org/security/2011/dsa-2331 | vendor advisory |