CVE-2011-4894 PUBLISHED

Reported by mitre · Published December 23, 2011

Tor before 0.2.2.34, when configured as a bridge, uses direct DirPort access instead of a Tor TLS connection for a directory fetch, which makes it easier for remote attackers to enumerate bridges by observing DirPort connections.

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a

Timeline

References

Open in Interactive Console →