Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2009-0939
HistoryMar 18, 2009 - 2:00 a.m.

CVE-2009-0939

2009-03-1802:00:08
Debian Security Bug Tracker
security-tracker.debian.org
13

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.004

Percentile

73.0%

Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to “Spec conformance,” as demonstrated using 192.168.0.

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.004

Percentile

73.0%