ID

VAR-201112-0165


CVE

CVE-2011-4896


TITLE

Tor Vulnerability in which important information is obtained

Trust: 0.8

sources: JVNDB: JVNDB-2011-003517

DESCRIPTION

Tor before 0.2.2.24-alpha continues to use a reachable bridge that was previously configured but is not currently configured, which might allow remote attackers to obtain sensitive information about clients in opportunistic circumstances by monitoring network traffic to the bridge port. Tor is prone to an information disclosure vulnerability. Successful exploits will allow attackers to obtain sensitive information to launch further attacks. Versions prior to Tor 0.2.2.24 are vulnerable

Trust: 1.89

sources: NVD: CVE-2011-4896 // JVNDB: JVNDB-2011-003517 // BID: 51283

AFFECTED PRODUCTS

vendor:tormodel:torscope:eqversion:0.2.1.29

Trust: 1.9

vendor:tormodel:torscope:eqversion:0.2.1.14

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.2.0.32

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.2.1.17

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.2.1.15

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.2.1.16

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.2.1.13

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.2.1.12

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.2.0.30

Trust: 1.6

vendor:tormodel:torscope:eqversion:0.1.1.20

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.0.14

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.0.13

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.0.12

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.0.11

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.0.10

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.9

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.8

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.7

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.6

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.5

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.4

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.3

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.2

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.10

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9.1

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.0.9

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.2.1.28

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.2.1.27

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.2.1.22

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.2.1.21

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.2.1.20

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.2.16

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.1.2.15

Trust: 1.3

vendor:tormodel:torscope:eqversion:0.2.2.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.21

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.27

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.28

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.8.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.28

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.24

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.25

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.31

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.26

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.6.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.29

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.27

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.26

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.24

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.7.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.25

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.31

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.25

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.20

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.34

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.22

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.10

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.21

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.21

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.11

Trust: 1.0

vendor:tormodel:torscope:lteversion:0.2.2.23

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.33

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.20

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.35

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.16

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.8

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.26

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.26

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.14

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.3

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.22

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.24

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.17

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.6

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.5

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.22

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.30

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.7.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.25

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.4

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.18

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.20

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.13

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.12

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.7.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.1.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.9

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.0.7

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.2.11

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.19

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.1.0.1

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.0.6.2

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.2.15

Trust: 1.0

vendor:tormodel:torscope:eqversion:0.2.1.1.19

Trust: 1.0

vendor:the tormodel:torscope:ltversion:0.2.2.24-alpha

Trust: 0.8

vendor:tormodel:torscope:eqversion:0.2.2.23

Trust: 0.6

vendor:tormodel:.21-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.20-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.19-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.18-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.17-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.16-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.15-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:.14-alphascope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.2

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.35

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.34

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.33

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.32

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.31

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.1.214

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.1.123

Trust: 0.3

vendor:tormodel:.5-alphascope:eqversion:0.1.1

Trust: 0.3

vendor:tormodel:.4-alphascope:eqversion:0.1.1

Trust: 0.3

vendor:tormodel:.3-alphascope:eqversion:0.1.1

Trust: 0.3

vendor:tormodel:.2-alphascope:eqversion:0.1.1

Trust: 0.3

vendor:tormodel:.1-alphascope:eqversion:0.1.1

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.118

Trust: 0.3

vendor:tormodel:torscope:eqversion:0.2.1.30

Trust: 0.3

vendor:tormodel:alpha-cvsscope:eqversion:0.1.2.1

Trust: 0.3

vendor:tormodel:torscope:neversion:0.2.224

Trust: 0.3

sources: BID: 51283 // JVNDB: JVNDB-2011-003517 // CNNVD: CNNVD-201112-432 // NVD: CVE-2011-4896

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2011-4896
value: MEDIUM

Trust: 1.0

NVD: CVE-2011-4896
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201112-432
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2011-4896
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2011-003517 // CNNVD: CNNVD-201112-432 // NVD: CVE-2011-4896

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.8

sources: JVNDB: JVNDB-2011-003517 // NVD: CVE-2011-4896

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201112-432

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201112-432

CONFIGURATIONS

sources: JVNDB: JVNDB-2011-003517

PATCH

title:Tor 0.2.2.24-alpha is outurl:https://blog.torproject.org/blog/tor-02224-alpha-out

Trust: 0.8

sources: JVNDB: JVNDB-2011-003517

EXTERNAL IDS

db:NVDid:CVE-2011-4896

Trust: 2.7

db:JVNDBid:JVNDB-2011-003517

Trust: 0.8

db:CNNVDid:CNNVD-201112-432

Trust: 0.6

db:BIDid:51283

Trust: 0.3

sources: BID: 51283 // JVNDB: JVNDB-2011-003517 // CNNVD: CNNVD-201112-432 // NVD: CVE-2011-4896

REFERENCES

url:https://blog.torproject.org/blog/tor-02224-alpha-out

Trust: 1.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2011-4896

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2011-4896

Trust: 0.8

url:http://www.torproject.org/index.html.en

Trust: 0.3

sources: BID: 51283 // JVNDB: JVNDB-2011-003517 // CNNVD: CNNVD-201112-432 // NVD: CVE-2011-4896

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 51283

SOURCES

db:BIDid:51283
db:JVNDBid:JVNDB-2011-003517
db:CNNVDid:CNNVD-201112-432
db:NVDid:CVE-2011-4896

LAST UPDATE DATE

2025-04-11T23:16:46.056000+00:00


SOURCES UPDATE DATE

db:BIDid:51283date:2011-04-12T00:00:00
db:JVNDBid:JVNDB-2011-003517date:2011-12-27T00:00:00
db:CNNVDid:CNNVD-201112-432date:2011-12-26T00:00:00
db:NVDid:CVE-2011-4896date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:BIDid:51283date:2011-04-12T00:00:00
db:JVNDBid:JVNDB-2011-003517date:2011-12-27T00:00:00
db:CNNVDid:CNNVD-201112-432date:2011-12-26T00:00:00
db:NVDid:CVE-2011-4896date:2011-12-23T03:59:22.130