CVE-2011-2769 Information

Description

Tor before 0.2.2.34 when configured as a bridge accepts the CREATE and CREATE_FAST values in the Command field of a cell within an OR connection that it initiated which allows remote relays to enumerate bridges by using these values.

Reference

http://www.debian.org/security/2011/dsa-2331 https://blog.torproject.org/blog/tor-02234-released-security-patches

Share on: