PT-2017-8356 · Tor · Tor Browser Launcher

Jann Horn

·

Published

2017-02-07

·

Updated

2017-02-28

·

CVE-2016-3180

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tor Browser Launcher versions prior to 0.2.4
Description The issue allows man-in-the-middle attackers to bypass the PGP signature verification and execute arbitrary code via a Trojan horse tar file and a signature file with the valid tarball and signature.
Recommendations For versions prior to 0.2.4, update to version 0.2.4 or later to resolve the issue. As a temporary workaround, consider verifying the integrity of downloaded files through alternative means until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-3180

Affected Products

Tor Browser Launcher