Candidate: CVE-2010-0385 PublicDate: 2010-01-25 19:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0385 http://archives.seul.org/or/announce/Jan-2010/msg00000.html Description: Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive information about bridge identities and bridge descriptors via a dbg-stability.txt directory query. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_tor: upstream_tor: needs-triage dapper_tor: ignored (reached end-of-life) hardy_tor: ignored (reached end-of-life) intrepid_tor: needs-triage (reached end-of-life) jaunty_tor: DNE karmic_tor: DNE lucid_tor: DNE maverick_tor: DNE natty_tor: not-affected oneiric_tor: not-affected devel_tor: not-affected