CVE-2006-3414 Information

Description

Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses which allows remote attackers to arbitrarily group users by providing preferential address resolution.

Reference

http://secunia.com/advisories/20514 http://security.gentoo.org/glsa/glsa-200606-04.xml http://tor.eff.org/cvs/tor/ChangeLog http://www.osvdb.org/25877

Share on: