CVE-2017-0377

HIGH

Tor - Information Disclosure

Title source: rule
STIX 2.1

Description

Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties by leveraging the existence of large families.

References (5)

Core 5
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://trac.torproject.org/projects/tor/ticket/22753
Third Party Advisory x_refsource_confirm
https://security-tracker.debian.org/CVE-2017-0377
Release Notes, Vendor Advisory x_refsource_confirm
https://blog.torproject.org/blog/tor-0309-released-security-update-clients

Scores

CVSS v3 7.5
EPSS 0.0048
EPSS Percentile 64.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (9)
n/a/Tor Tor
torproject/tor 0.3.0.1 alpha
torproject/tor 0.3.0.2 alpha
torproject/tor 0.3.0.3 alpha
torproject/tor 0.3.0.4
torproject/tor 0.3.0.5
torproject/tor 0.3.0.6
torproject/tor 0.3.0.7
torproject/tor 0.3.0.8
Published Jul 02, 2017
Tracked Since Feb 18, 2026