Total vulnerabilities in the database
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.
Software | From | Fixed in |
---|---|---|
tor_project / tor | 0.3.1 | 0.3.1.9 |
tor_project / tor | 0.3.0 | 0.3.0.13 |
tor_project / tor | 0.2.9 | 0.2.9.14 |
tor_project / tor | 0.2.6 | 0.2.8.17 |
tor_project / tor | - | 0.2.5.16 |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |