Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-2768
HistoryDec 23, 2011 - 12:00 a.m.

CVE-2011-2768

2011-12-2300:00:00
ubuntu.com
ubuntu.com
13

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS

0.001

Percentile

42.9%

Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS
certificate chain as part of an outgoing OR connection, which allows remote
relays to bypass intended anonymity properties by reading this chain and
then determining the set of entry guards that the client or bridge had
selected.

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

EPSS

0.001

Percentile

42.9%