Skip to content

Commit 07ecbf9

Browse files
committed
[CVE-2021-39246] Update, occurs in default conditions
1 parent c999864 commit 07ecbf9

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

advisories/SICK-2021-111.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ Tor Browser on Windows, macOS, Linux
2121

2222
### Vulnerability Details
2323

24-
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. If --log or --verbose is used, exact timestamps of these onion-service visits are logged locally, and an attacker might be able to compare them to timestamp data collected by the destination server (or collected by a rogue site within the Tor network).
24+
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact timestamps of these onion-service visits are logged locally, and an attacker might be able to compare them to timestamp data collected by the destination server (or collected by a rogue site within the Tor network). This occurs by default, with or without verbose.
2525

2626
### Vendor Response
2727
Open pull request in relation to timestamp logging as v2 will be deprecated soon:
@@ -92,6 +92,8 @@ Sep 24 16:29:02.000 [warn] Warning! You've just connected to a v2 onion address.
9292

9393
[https://gitlab.torproject.org/tpo/core/tor/-/merge_requests/434](https://gitlab.torproject.org/tpo/core/tor/-/merge_requests/434)
9494

95+
[https://hackerone.com/reports/1250273](https://hackerone.com/reports/1250273)
96+
9597
### Researchers
9698
- *Sick Codes* [https://github.com/sickcodes](https://github.com/sickcodes) || [https://twitter.com/sickcodes](https://twitter.com/sickcodes)
9799

0 commit comments

Comments
 (0)