Information disclosure in Tor - CVE-2011-4897

 

Information disclosure in Tor - CVE-2011-4897

Published: December 23, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU44433
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-4897
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Tor before 0.2.2.25-alpha, when configured as a relay without the Nickname configuration option, uses the local hostname as the Nickname value, which allows remote attackers to obtain potentially sensitive information by reading this value.


Affected software

Tor

How to mitigate CVE-2011-4897

Install update from vendor's website.


External References

Related Security Bulletins