CVE-2006-3411 Information

Description

TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.

Reference

http://secunia.com/advisories/20514 http://security.gentoo.org/glsa/glsa-200606-04.xml http://tor.eff.org/cvs/tor/ChangeLog http://www.osvdb.org/25876

Share on: