ID

VAR-201112-0164


CVE

CVE-2011-4895


TITLE

Tor Enumerated bridge vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2011-003516

DESCRIPTION

Tor before 0.2.2.34, when configured as a bridge, sets up circuits through a process different from the process used by a client, which makes it easier for remote attackers to enumerate bridges by observing circuit building. Tor is prone to a bridge enumeration weakness. Successful exploits will allow attackers to obtain sensitive information to launch further attacks. Versions prior to Tor 0.2.2.34 are vulnerable

Trust: 1.89

sources: NVD: CVE-2011-4895 // JVNDB: JVNDB-2011-003516 // BID: 51279

AFFECTED PRODUCTS

vendor:tormodel:torscope:eqversion:0.0.7

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.7.1

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.6.1

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.6.2

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.5

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.3

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.2

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.6

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.4

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.0.7.2

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.1.1.20

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.0.14

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.0.13

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.0.12

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.0.11

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.0.10

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.9

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.8

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.7

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.6

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.5

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.4

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.3

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.2

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.10

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.1

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.2.1.21

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.2.1.20

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.2.16

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.2.15

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.2.2.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.21

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.28

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.27

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.28

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.8.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.28

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.32

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.29

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.24

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.25

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.31

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.26

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.29

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.22

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.27

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.27

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.26

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.24

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.30

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.7.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.25

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.31

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.25

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.20

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.34

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.22

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.21

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.21

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.32

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.33

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.20

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.35

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.26

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.26

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.14

Trust: 1.0

vendor:tormodel:torscope:lteversion:0.2.2.33

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.22

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.24

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.22

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.30

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.25

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.29

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.20

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.19

Trust: 1.0

vendor:the tormodel:torscope:ltversion:0.2.2.34

Trust: 0.8

vendor:tormodel:.21-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.20-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.19-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.18-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.17-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.16-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.15-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.14-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.35

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.34

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.33

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.32

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.31

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.1.214

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.1.123

Trust: 0.3

vendor:tormodel:.5-alphascope:eqversion:0.1.1

Trust: 0.3

vendor:tormodel:.4-alphascope:eqversion:0.1.1

Trust: 0.3

vendor:tormodel:.3-alphascope:eqversion:0.1.1

Trust: 0.3

vendor:tormodel:.2-alphascope:eqversion:0.1.1

Trust: 0.3

vendor:tormodel:.1-alphascope:eqversion:0.1.1

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.118

Trust: 0.3

vendor:tormodel:alpha-cvsscope:eqversion:0.1.2.1

Trust: 0.3

vendor:tormodel:torscope:neversion:0.2.2.34

Trust: 0.3

sources: BID: 51279 // JVNDB: JVNDB-2011-003516 // CNNVD: CNNVD-201112-431 // NVD: CVE-2011-4895

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2011-4895
value: MEDIUM

Trust: 1.0

NVD: CVE-2011-4895
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201112-431
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2011-4895
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2011-003516 // CNNVD: CNNVD-201112-431 // NVD: CVE-2011-4895

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.8

sources: JVNDB: JVNDB-2011-003516 // NVD: CVE-2011-4895

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201112-431

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201112-431

CONFIGURATIONS

sources: JVNDB: JVNDB-2011-003516

PATCH

title:Tor 0.2.2.34 is released (security patches)url:https://blog.torproject.org/blog/tor-02234-released-security-patches

Trust: 0.8

sources: JVNDB: JVNDB-2011-003516

EXTERNAL IDS

db:NVDid:CVE-2011-4895

Trust: 2.7

db:JVNDBid:JVNDB-2011-003516

Trust: 0.8

db:CNNVDid:CNNVD-201112-431

Trust: 0.6

db:BIDid:51279

Trust: 0.3

sources: BID: 51279 // JVNDB: JVNDB-2011-003516 // CNNVD: CNNVD-201112-431 // NVD: CVE-2011-4895

REFERENCES

url:https://blog.torproject.org/blog/tor-02234-released-security-patches

Trust: 1.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2011-4895

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2011-4895

Trust: 0.8

url:http://www.torproject.org/index.html.en

Trust: 0.3

sources: BID: 51279 // JVNDB: JVNDB-2011-003516 // CNNVD: CNNVD-201112-431 // NVD: CVE-2011-4895

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 51279

SOURCES

db:BIDid:51279
db:JVNDBid:JVNDB-2011-003516
db:CNNVDid:CNNVD-201112-431
db:NVDid:CVE-2011-4895

LAST UPDATE DATE

2025-04-11T22:56:19.790000+00:00


SOURCES UPDATE DATE

db:BIDid:51279date:2011-10-27T00:00:00
db:JVNDBid:JVNDB-2011-003516date:2011-12-27T00:00:00
db:CNNVDid:CNNVD-201112-431date:2011-12-26T00:00:00
db:NVDid:CVE-2011-4895date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:BIDid:51279date:2011-10-27T00:00:00
db:JVNDBid:JVNDB-2011-003516date:2011-12-27T00:00:00
db:CNNVDid:CNNVD-201112-431date:2011-12-26T00:00:00
db:NVDid:CVE-2011-4895date:2011-12-23T03:59:22.097