CVE-2007-4098

Source
https://nvd.nist.gov/vuln/detail/CVE-2007-4098
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2007-4098.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2007-4098
Published
2007-07-30T21:17:00Z
Modified
2024-11-21T00:34:46Z
Summary
[none]
Details

Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.

References

Affected packages

Debian:11 / tor

Package

Name
tor
Purl
pkg:deb/debian/tor?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.2.15-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / tor

Package

Name
tor
Purl
pkg:deb/debian/tor?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.2.15-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / tor

Package

Name
tor
Purl
pkg:deb/debian/tor?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.2.15-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}