VDB
DEBIAN-CVE-2011-4894
DEBIAN-CVE-2011-4894
PUBLISHED
Tor before 0.2.2.34, when configured as a bridge, uses direct DirPort access instead of a Tor TLS connection for a directory fetch, which makes it easier for remote attackers to enumerate bridges by observing DirPort connections.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | tor | 0, 0, 0 |
| Debian:14 | tor | 0, 0, 0 |
| Debian:11 | tor | 0, 0, 0 |
| Debian:12 | tor | 0, 0, 0 |
Timeline
- Dec 23, 2011 CVE Published
- Apr 28, 2026 CVE Updated