DEBIAN-CVE-2009-0654

Source
https://security-tracker.debian.org/tracker/CVE-2009-0654
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0654.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2009-0654
Upstream
Published
2009-02-20T19:30:00Z
Modified
2026-09-17T06:47:43Z
Summary
[none]
Details

Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell, and then observing cell recognition errors at the exit router. NOTE: the vendor disputes the significance of this issue, noting that the product's design "accepted end-to-end correlation as an attack that is too expensive to solve."

References

Affected packages

Debian:12 / tor

Package

Name
tor
Purl
pkg:deb/debian/tor?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.4.7.13-1
0.4.7.16-1
0.4.8.4-2
0.4.8.5-1
0.4.8.6-1
0.4.8.7-1
0.4.8.8-1
0.4.8.9-1~bpo11+1
0.4.8.9-1~bpo12+1
0.4.8.9-1
0.4.8.10-1~bpo11+1
0.4.8.10-1~bpo12+1
0.4.8.10-1
0.4.8.11-1~bpo11+1
0.4.8.11-1~bpo12+1
0.4.8.11-1
0.4.8.12-1~bpo11+1
0.4.8.12-1~bpo12+1
0.4.8.12-1
0.4.8.12-1.1
0.4.8.13-1
0.4.8.13-2~bpo12+1
0.4.8.13-2
0.4.8.14-1~bpo12+1
0.4.8.14-1
0.4.8.16-1
0.4.8.21-1~bpo12+1
0.4.8.21-1~bpo13+1
0.4.8.21-1~bpo13+2
0.4.8.21-1
0.4.8.22-1~bpo12+1
0.4.8.22-1~bpo13+1
0.4.8.22-1
0.4.9.5-1
0.4.9.5-2~bpo12+1
0.4.9.5-2~bpo13+1
0.4.9.5-2
0.4.9.6-0+deb12u1
0.4.9.6-1~bpo12+1
0.4.9.6-1~bpo13+1
0.4.9.6-1
0.4.9.8-0+deb12u1
0.4.9.8-1~bpo12+1
0.4.9.8-1~bpo13+1
0.4.9.8-1
0.4.9.9-1~bpo13+1
0.4.9.9-1
0.4.9.11-0+deb12u1
0.4.9.11-1~bpo13+1
0.4.9.11-1
0.4.9.12-2
0.4.9.12-3
0.4.9.12-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0654.json"

Debian:13 / tor

Package

Name
tor
Purl
pkg:deb/debian/tor?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.4.8.16-1
0.4.8.21-1~bpo12+1
0.4.8.21-1~bpo13+1
0.4.8.21-1~bpo13+2
0.4.8.21-1
0.4.8.22-1~bpo12+1
0.4.8.22-1~bpo13+1
0.4.8.22-1
0.4.9.5-1
0.4.9.5-2~bpo12+1
0.4.9.5-2~bpo13+1
0.4.9.5-2
0.4.9.6-0+deb13u1
0.4.9.6-1~bpo12+1
0.4.9.6-1~bpo13+1
0.4.9.6-1
0.4.9.8-0+deb13u1
0.4.9.8-1~bpo12+1
0.4.9.8-1~bpo13+1
0.4.9.8-1
0.4.9.9-1~bpo13+1
0.4.9.9-1
0.4.9.11-0+deb13u1
0.4.9.11-1~bpo13+1
0.4.9.11-1
0.4.9.12-0+deb13u1
0.4.9.12-0+deb13u2
0.4.9.12-2
0.4.9.12-3
0.4.9.12-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0654.json"

Debian:14 / tor

Package

Name
tor
Purl
pkg:deb/debian/tor?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.4.8.16-1
0.4.8.21-1~bpo12+1
0.4.8.21-1~bpo13+1
0.4.8.21-1~bpo13+2
0.4.8.21-1
0.4.8.22-1~bpo12+1
0.4.8.22-1~bpo13+1
0.4.8.22-1
0.4.9.5-1
0.4.9.5-2~bpo12+1
0.4.9.5-2~bpo13+1
0.4.9.5-2
0.4.9.6-1~bpo12+1
0.4.9.6-1~bpo13+1
0.4.9.6-1
0.4.9.8-1~bpo12+1
0.4.9.8-1~bpo13+1
0.4.9.8-1
0.4.9.9-1~bpo13+1
0.4.9.9-1
0.4.9.11-1~bpo13+1
0.4.9.11-1
0.4.9.12-2
0.4.9.12-3
0.4.9.12-4

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-0654.json"