Back to search
CVE-2008-5398
Published: Dec 9, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the destination hostname of a refused stream.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
tor-clientdnsreject-security-bypass(47102)
vdb-entry
x_refsource_XF
34583
third-party-advisory
x_refsource_SECUNIA
32648
vdb-entry
x_refsource_BID
33025
third-party-advisory
x_refsource_SECUNIA
ADV-2008-3366
vdb-entry
x_refsource_VUPEN
http://blog.torproject.org/blog/tor-0.2.0.32-released
x_refsource_CONFIRM
GLSA-200904-11
vendor-advisory
x_refsource_GENTOO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now