CVE-2010-0383 Information

Description

Tor before 0.2.1.22 and 0.2.2.x before 0.2.2.7-alpha uses deprecated identity keys for certain directory authorities which makes it easier for man-in-the-middle attackers to compromise the anonymity of traffic sources and destinations.

Reference

http://archives.seul.org/or/announce/Jan-2010/msg00000.html http://archives.seul.org/or/talk/Jan-2010/msg00161.html http://archives.seul.org/or/talk/Jan-2010/msg00162.html http://archives.seul.org/or/talk/Jan-2010/msg00165.html http://osvdb.org/61977 http://secunia.com/advisories/38198 http://www.securityfocus.com/bid/37901

Share on: