[or-announce] 20070802 Tor 0.1.2.16 is releasedmailing list
http://archives.seul.org/or/announce/Aug-2007/msg00000.html CVE-2007-4174
Tor 0.1.2.15 - ControlPort Missing Authentication Unauthorized Access
Record summary
CVE-2007-4174 has a selected CVSS score of 5.8; EIP currently links 2 catalogued exploits.
Description
Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified impact via HTTP POST data containing commands without valid authentication, as demonstrated by an HTML form (1) hosted on a web site or (2) injected by a Tor exit node.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBTor 0.1.2.15 - ControlPort Missing Authentication Unauthorized AccessExploitDB exploitby anonymousNot analyzed1 file
ExploitDBTor < 0.1.2.16 - ControlPort Remote RewriteExploitDB exploitby elgCrewNot analyzed1 file
References
10[or-announce] 20070901 Tor security advisory: cross-protocol http form attackmailing list
http://archives.seul.org/or/announce/Sep-2007/msg00000.html 36271vdb entry
http://osvdb.org/36271 26301Third-party advisory
http://secunia.com/advisories/26301 25188vdb entry
http://www.securityfocus.com/bid/25188 1018510vdb entry
http://www.securitytracker.com/id?1018510 ADV-2007-2768vdb entry
http://www.vupen.com/english/advisories/2007/2768 tor-controlport-security-bypass(35784)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35784 tor-control-command-execution(36407)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/36407 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4174