PT-2019-12773 · Tor+2 · Tor Browser+1

Published

2019-05-27

·

Updated

2023-03-24

·

CVE-2019-12383

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tor Browser versions prior to 8.0.1
Description The issue allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a "Don't send my language" setting. This is an information exposure issue.
Recommendations For versions prior to 8.0.1, update to version 8.0.1 or later to resolve the issue.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2019-12383
ECHO-21A6-33D6-5465

Affected Products

Debian
Tor Browser