CVE-2006-3414
EPSS 0.49%
Description
Tor before 0.1.1.20 supports server descriptors that contain hostnames instead of IP addresses, which allows remote attackers to arbitrarily group users by providing preferential address resolution.
How to fix CVE-2006-3414
To remediate CVE-2006-3414, upgrade the affected package to a fixed version below.
- Debian/tor—upgrade to 0.1.1.20-1 or later
Is CVE-2006-3414 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.1.1.20-1