CVE-2017-0377

Source
https://cve.org/CVERecord?id=CVE-2017-0377
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-0377.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-0377
Downstream
Related
Published
2017-07-02T15:29:00Z
Modified
2026-05-17T12:01:13Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties by leveraging the existence of large families.

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:a:torproject:tor:0.3.0.1:alpha:*:*:*:*:*:*",
                "cpe:2.3:a:torproject:tor:0.3.0.4:*:*:*:*:*:*:*",
                "cpe:2.3:a:torproject:tor:0.3.0.5:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "last_affected":  "0.3.0.1-alpha"
                },
                {
                    "last_affected":  "0.3.0.4"
                },
                {
                    "last_affected":  "0.3.0.4"
                },
                {
                    "last_affected":  "0.3.0.5"
                },
                {
                    "last_affected":  "0.3.0.5"
                }
            ],
            "source":  "CPE_FIELD",
            "vendor_product":  "torproject:tor"
        }
    ]
}
References

Affected packages