CVE-2008-5398

high

Description

Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the destination hostname of a refused stream.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/47102

http://www.vupen.com/english/advisories/2008/3366

http://www.securityfocus.com/bid/32648

http://security.gentoo.org/glsa/glsa-200904-11.xml

http://secunia.com/advisories/34583

http://secunia.com/advisories/33025

http://blog.torproject.org/blog/tor-0.2.0.32-released

Details

Source: Mitre, NVD

Published: 2008-12-09

Updated: 2017-08-08

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: High