CVE-2013-7295
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge platforms, does not properly generate random numbers for (1) relay identity keys and (2) hidden-service identity keys, which might make it easier for remote attackers to bypass cryptographic protection mechanisms via unspecified vectors.
Tor anteriores a 0.2.4.20, cuando OpenSSL 1.x es utilizado en conjunción con cierto ajuste de HardwareAccel en las plataformas Intel Sandy Bridge e Ivy Bridge, no genera apropiadamente números aleatorios para (1) claves de identidad de relay y (2) claves de identidad de servicio oculto, lo cual podría hacer más fácil para los atacantes remotos sortear mecanismos de protección criptográfica a través de vectores no especificados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-01-17 CVE Reserved
- 2014-01-17 CVE Published
- 2023-11-30 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.opensuse.org/opensuse-updates/2014-01/msg00095.html | 2014-02-12 | |
https://lists.torproject.org/pipermail/tor-talk/2013-December/031483.html | 2014-02-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | <= 0.2.4.19 Search vendor "Torproject" for product "Tor" and version " <= 0.2.4.19" | - |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.1 Search vendor "Torproject" for product "Tor" and version "0.2.4.1" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.2 Search vendor "Torproject" for product "Tor" and version "0.2.4.2" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.3 Search vendor "Torproject" for product "Tor" and version "0.2.4.3" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.4 Search vendor "Torproject" for product "Tor" and version "0.2.4.4" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.5 Search vendor "Torproject" for product "Tor" and version "0.2.4.5" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.6 Search vendor "Torproject" for product "Tor" and version "0.2.4.6" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.7 Search vendor "Torproject" for product "Tor" and version "0.2.4.7" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.8 Search vendor "Torproject" for product "Tor" and version "0.2.4.8" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.9 Search vendor "Torproject" for product "Tor" and version "0.2.4.9" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.10 Search vendor "Torproject" for product "Tor" and version "0.2.4.10" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.11 Search vendor "Torproject" for product "Tor" and version "0.2.4.11" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.12 Search vendor "Torproject" for product "Tor" and version "0.2.4.12" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.13 Search vendor "Torproject" for product "Tor" and version "0.2.4.13" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.14 Search vendor "Torproject" for product "Tor" and version "0.2.4.14" | alpha |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.15 Search vendor "Torproject" for product "Tor" and version "0.2.4.15" | rc |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.16 Search vendor "Torproject" for product "Tor" and version "0.2.4.16" | rc |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.17 Search vendor "Torproject" for product "Tor" and version "0.2.4.17" | rc |
Affected
| ||||||
Torproject Search vendor "Torproject" | Tor Search vendor "Torproject" for product "Tor" | 0.2.4.18 Search vendor "Torproject" for product "Tor" and version "0.2.4.18" | rc |
Affected
|