Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-5398
HistoryDec 09, 2008 - 12:00 a.m.

CVE-2008-5398

2008-12-0900:00:00
ubuntu.com
ubuntu.com
9

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.006

Percentile

79.5%

Tor before 0.2.0.32 does not properly process the
ClientDNSRejectInternalAddresses configuration option in situations where
an exit relay issues a policy-based refusal of a stream, which allows
remote exit relays to have an unknown impact by mapping an internal IP
address to the destination hostname of a refused stream.

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.006

Percentile

79.5%