CVE-2010-0385 Information

Description

Tor before 0.2.1.22 and 0.2.2.x before 0.2.2.7-alpha when functioning as a bridge directory authority allows remote attackers to obtain sensitive information about bridge identities and bridge descriptors via a dbg-stability.txt directory query.

Reference

http://archives.seul.org/or/announce/Jan-2010/msg00000.html http://archives.seul.org/or/talk/Jan-2010/msg00162.html http://secunia.com/advisories/38198 http://www.osvdb.org/61865 http://www.securityfocus.com/bid/37901

Share on: