CVE-2006-3418

Publication date 7 July 2006

Last updated 17 July 2025


Ubuntu priority

Tor before 0.1.1.20 does not validate that a server descriptor’s fingerprint line matches its identity key, which allows remote attackers to spoof the fingerprint line, which might be trusted by users or other applications.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
tor 9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid
Fixed 0.1.1.20-1
8.04 LTS hardy
Fixed 0.1.1.20-1
7.10 gutsy
Fixed 0.1.1.20-1
7.04 feisty
Fixed 0.1.1.20-1
6.10 edgy
Fixed 0.1.1.20-1
6.06 LTS dapper Ignored end of life