CVE-2007-1103
Publication date 26 February 2007
Last updated 24 July 2024
Ubuntu priority
Tor does not verify a node’s uptime and bandwidth advertisements, which allows remote attackers who operate a low resource node to make false claims of greater resources, which places the node into use for many circuits and compromises the anonymity of traffic sources and destinations.
Status
Package | Ubuntu Release | Status |
---|---|---|
tor | 11.10 oneiric |
Not affected
|
11.04 natty |
Not affected
|
|
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
9.10 karmic | Not in release | |
9.04 jaunty | Not in release | |
8.10 intrepid | Ignored end of life, was needed | |
8.04 LTS hardy | Ignored end of life | |
7.10 gutsy | Ignored end of life, was needed | |
7.04 feisty | Ignored end of life, was needed | |
6.10 edgy | Ignored end of life, was needed | |
6.06 LTS dapper | Ignored end of life |