« Volver al listado

CVE-2017-8822

Estado: ModificadaBaja (3.7)—

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-8822",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 3.7,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@debian.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9",
          "versions": [
            {
              "status": "affected",
              "version": "Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-12-03T07:29:00.413",
  "references": [
    {
      "url": "https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@debian.org"
    },
    {
      "url": "https://bugs.torproject.org/21534",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "security@debian.org"
    },
    {
      "url": "https://bugs.torproject.org/24333",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@debian.org"
    },
    {
      "url": "https://www.debian.org/security/2017/dsa-4054",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@debian.org"
    },
    {
      "url": "https://blog.torproject.org/new-stable-tor-releases-security-fixes-0319-03013-02914-02817-02516",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.torproject.org/21534",
      "tags": [
        "Issue Tracking",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.torproject.org/24333",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.debian.org/security/2017/dsa-4054",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-417"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012."
    },
    {
      "lang": "es",
      "value": "En Tor, en versiones anteriores a la 0.2.5.16; de la versión 0.2.6 hasta la 0.2.8 anterior a la 0.2.8.17; versiones 0.2.9 anteriores a la 0.2.9.14; versiones 0.3.0 anteriores a la 0.3.0.13 y versiones 0.3.1 anteriores a la 0.3.1.9, los relays (que contienen descriptores descargados de forma incompleta) pueden escogerse a sí mismos en una ruta, lo que da lugar a una degradación de anonimato. Esto también se conoce como TROVE-2017-012."
    }
  ],
  "lastModified": "2026-06-17T01:27:01.473",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "067DE048-F786-4E63-98E6-6FD6415DD3A5",
              "versionEndExcluding": "0.2.5.16"
            },
            {
              "criteria": "cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5372249B-59F8-4866-B4D3-F52980FCC269",
              "versionEndExcluding": "0.2.8.17",
              "versionStartIncluding": "0.2.6"
            },
            {
              "criteria": "cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0739CCD-DE8F-4A44-91CD-986C4644045F",
              "versionEndExcluding": "0.2.9.14",
              "versionStartIncluding": "0.2.9"
            },
            {
              "criteria": "cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E623D0FC-453C-4D7A-8328-C4C252EEC976",
              "versionEndExcluding": "0.3.0.13",
              "versionStartIncluding": "0.3.0"
            },
            {
              "criteria": "cpe:2.3:a:tor_project:tor:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "249879F0-6A12-41C2-9559-020021080696",
              "versionEndExcluding": "0.3.1.9",
              "versionStartIncluding": "0.3.1"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@debian.org"
}