2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2005-2643" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2005-08-23T04:00:00.000" ,
2024-11-21 23:11:37 +00:00
"lastModified" : "2024-11-21T00:00:03.007" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Tor 0.1.0.13 and earlier, and experimental versions 0.1.1.4-alpha and earlier, does not reject certain weak keys when using ephemeral Diffie-Hellman (DH) handshakes, which allows malicious Tor servers to obtain the keys that a client uses for other systems in the circuit."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:L/Au:N/C:P/I:N/A:N" ,
2024-11-21 23:11:37 +00:00
"baseScore" : 5.0 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "NONE" ,
2024-11-21 23:11:37 +00:00
"availabilityImpact" : "NONE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 10.0 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-Other"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.0.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6E2103A8-0F3F-4226-A5D8-4BF239FD6636"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.0.9.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FDA35257-80F6-4DDF-94EF-ABE1ED039ED8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.0.9.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0490AB18-A839-400D-88E2-D918B1EEFA00"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.0.9.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DBED980F-A8B9-4C44-957C-FD18867B1799"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.0.9.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3E033E0C-C7F6-4910-A795-28BA60E9431A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.0.9.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5AAAACA5-F431-4D83-B04D-EC9A81C96184"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.0.9.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A1D5B46C-E7D3-495F-861C-12324F09EC9F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.0.9.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "639E3063-34CC-4AE2-B055-92D36ECAADF2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.0.9.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C5305AF8-E26C-44A1-B546-AAC5D1C2D053"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.0.9.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "48DCAB29-4EF2-4A50-A941-DA5D89E27D51"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7A8F70D6-4B9C-4131-A419-4AD9325DFFC9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "48B8A291-E1F7-444F-8C5B-C3C38541B3D1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "24581D9F-02AF-42E6-A3D7-9CAD43E26477"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3B978E3E-69D7-46BD-BD88-1409A546FF66"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E7FED829-128A-4F87-9838-AD0C9C11E458"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3A39B543-5978-46FC-AF85-D635D87E3B92"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4CE0BE0D-F509-4A91-BDD7-A0A8324498D2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "803498D9-C750-4D16-8ADF-2F98E71888A4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "65F6A78C-76E9-4A5F-92BD-B16D1CBE934F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C04309D4-FEA8-47EA-BB9A-8CBD341B475F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8607F3C9-F185-4B87-8A1B-B9495A4F244D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.12:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "525A0E09-D4CF-42AA-8EB2-47E0E6CBA179"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.0.13:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "667201BB-5FDA-4E51-B865-0AF8507DBCDA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.1.1_alpha:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "811CE708-CEE6-4B0F-98E5-E138C06EA382"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.1.2_alpha:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6860F802-FEC2-449A-A5FC-AFACCA8633CC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.1.3_alpha:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A4CA23F0-7C49-430E-AD20-7C7BDCC1EEC8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:tor:tor:0.1.1.4_alpha:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D4D9E677-01D2-4800-82AA-F5585475D500"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://archives.seul.org/or/announce/Aug-2005/msg00002.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://marc.info/?l=bugtraq&m=112448002732443&w=2" ,
"source" : "cve@mitre.org"
} ,
2024-04-04 08:46:00 +00:00
{
"url" : "http://secunia.com/advisories/16424" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
2023-04-24 12:24:31 +02:00
{
"url" : "http://securitytracker.com/id?1014739" ,
"source" : "cve@mitre.org"
2024-11-21 23:11:37 +00:00
} ,
{
"url" : "http://archives.seul.org/or/announce/Aug-2005/msg00002.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://marc.info/?l=bugtraq&m=112448002732443&w=2" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://secunia.com/advisories/16424" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "http://securitytracker.com/id?1014739" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}