|
Tor Cryptographic Handshake Remote Information Disclosure Vulnerability
Tor is susceptible to a remote information disclosure vulnerability. This issue is due to a flaw in the implementation of the Diffie-Hellman key exchange protocol. Specifically, certain values used during the Diffie-Hellman key exchange protocol are insecure, and when used, lead to the ability of attackers to access the negotiated encryption keys. This vulnerability allows attackers to gain access to the negotiated keys used to encrypt the communications between Tor servers and clients. This allows attackers to read or modify all the traffic that is sent from the targeted user over the Tor network. The anonymity, confidentiality, and integrity guarantees of the network are lost through the exploitation of this issue. |
|
|
Privacy Statement |