CVE-2009-0654
Last modified
CVE-2009-0654 is a vulnerability of currently unknown severity. Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell, and then observing cell recognition errors at the exit router. NOTE: the vendor disputes the significance of this issue, noting that the product's design "accepted end-to-end correlation as an attack that is too expensive to solve.". EPSS estimates a 2.12% chance of exploitation in the next 30 days.
Description
Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit router, to confirm that a sender and receiver are communicating via vectors involving (1) replaying, (2) modifying, (3) inserting, or (4) deleting a single cell, and then observing cell recognition errors at the exit router. NOTE: the vendor disputes the significance of this issue, noting that the product's design "accepted end-to-end correlation as an attack that is too expensive to solve."
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Tor | Tor | <= 0.2.0.34 | Alpha |
| Tor | Tor | 0.2.0.1 | Alpha |
| Tor | Tor | 0.2.0.2 | Alpha |
| Tor | Tor | 0.2.0.3 | Alpha |
| Tor | Tor | 0.2.0.4 | Alpha |
| Tor | Tor | 0.2.0.5 | Alpha |
| Tor | Tor | 0.2.0.6 | Alpha |
| Tor | Tor | 0.2.0.7 | Alpha |
| Tor | Tor | 0.2.0.8 | Alpha |
| Tor | Tor | 0.2.0.9 | Alpha |
| Tor | Tor | 0.2.0.10 | Alpha |
| Tor | Tor | 0.2.0.11 | Alpha |
| Tor | Tor | 0.2.0.12 | Alpha |
| Tor | Tor | 0.2.0.13 | Alpha |
| Tor | Tor | 0.2.0.14 | Alpha |
| Tor | Tor | 0.2.0.15 | Alpha |
| Tor | Tor | 0.2.0.16 | Alpha |
| Tor | Tor | 0.2.0.17 | Alpha |
| Tor | Tor | 0.2.0.18 | Alpha |
| Tor | Tor | 0.2.0.19 | Alpha |
| Tor | Tor | 0.2.0.20 | Alpha |
| Tor | Tor | 0.2.0.21 | Alpha |
| Tor | Tor | 0.2.0.22 | Alpha |
| Tor | Tor | 0.2.0.23 | Alpha |
| Tor | Tor | 0.2.0.24 | Alpha |
| Tor | Tor | 0.2.0.25 | Alpha |
| Tor | Tor | 0.2.0.26 | Alpha |
| Tor | Tor | 0.2.0.27 | Alpha |
| Tor | Tor | 0.2.0.28 | Alpha |
| Tor | Tor | 0.2.0.29 | Alpha |
| Tor | Tor | 0.2.0.30 | Alpha |
| Tor | Tor | 0.2.0.31 | Alpha |
| Tor | Tor | 0.2.0.32 | Alpha |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0654?
How severe is CVE-2009-0654?
How do I fix CVE-2009-0654?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0648Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2009-0649The web browser in Symbian OS on the Nokia N95 cell phone al…
- CVE-2009-0650Stack-based buffer overflow in the GetStatsFromLine function…
- CVE-2009-0651Unspecified vulnerability in the Veritas network daemon (aka…
- CVE-2009-0652The Internationalized Domain Names (IDN) blacklist in Mozill…
- CVE-2009-0653OpenSSL, probably 0.9.6, does not verify the Basic Constrain…
- CVE-2009-0655Lenovo Veriface III allows physically proximate attackers to…
- CVE-2009-0656Asus SmartLogon 1.0.0005 allows physically proximate attacke…
- CVE-2009-0657Toshiba Face Recognition 2.0.2.32 allows physically proximat…
- CVE-2009-0658Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat…7.8
- CVE-2009-0659Stack-based buffer overflow in the GetStatsFromLine function…
- CVE-2009-0660Multiple cross-site scripting (XSS) vulnerabilities in Mahar…
Are you affected by CVE-2009-0654?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
