Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Tor ControlPort Missing Authentication Unauthorized Access Vulnerability

Tor is prone to an unauthorized-access vulnerability due to a design error when handling multiple connections to the ControlPort.

An attacker can exploit this issue to reconfigure Tor and significantly weaken the anonymity provided by the software.

Tor 0.1.2.15 is confirmed vulnerable; previous versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus