Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an inbound RELAY_EARLY cell is received by a client, which makes it easier for remote attackers to conduct traffic-confirmation attacks by using the pattern of RELAY and RELAY_EARLY cells as a means of communicating information about hidden service names.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade tor | Jul 30, 2024 | Jul 30, 2014 |
| Freebsd | — | Upgrade tor-develUpgrade tor | Dec 10, 2025 | Jul 30, 2014 |
| Suse | — | Upgrade tor-debugsourceUpgrade torUpgrade tor-debuginfo | Dec 18, 2015 | Jul 30, 2014 |
| Ubuntu | — | Upgrade tor | Nov 19, 2024 | Jul 30, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub