Security Advisory

CVE-2005-2643

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-08-21 04:00:00
Last updated 2024-08-07 22:45:01
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Tor 0.1.0.13 and earlier, and experimental versions 0.1.1.4-alpha and earlier, does not reject certain weak keys when using ephemeral Diffie-Hellman (DH) handshakes, which allows malicious Tor servers to obtain the keys that a client uses for other systems in the circuit.