PT-2008-6515 · Tor · Tor

Rovv

·

Published

2008-12-08

·

Updated

2017-08-08

·

CVE-2008-5398

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tor versions prior to 0.2.0.32
Description The issue arises from improper processing of the ClientDNSRejectInternalAddresses configuration option when an exit relay issues a policy-based refusal of a stream. This allows remote exit relays to potentially map an internal IP address to the destination hostname of a refused stream, although the exact impact is unknown.
Recommendations For versions prior to 0.2.0.32, update to version 0.2.0.32 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5398

Affected Products

Tor