CVE-2008-5398
EPSS 0.84%
Description
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the destination hostname of a refused stream.
How to fix CVE-2008-5398
To remediate CVE-2008-5398, upgrade the affected package to a fixed version below.
- Debian/tor—upgrade to 0.2.0.32-1 or later
Is CVE-2008-5398 being exploited?
Low — EPSS is 0.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.2.0.32-1