CVE-2011-2768 PUBLISHED CVSS 5.800000190734863 MEDIUM

Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows remote relays to bypass intended anonymity properties by reading this chain and then determining the set of entry guards that the client or bridge had selected.

EPSS 0.14% · 33.4th percentile

Risk Scores

CVSS v2.0
5.800000190734863
EPSS Score
0.14%
33.4th percentile

Affected Products

VendorProductVersions
n/an/an/a, n/a
tortor0, 0.0.2, 0.0.3

Timeline

References

Open in Interactive Console →