Back to Database
Status published
Medium
CVE-2006-3415
Tor before 0.1.1.20 uses improper logic to validate the "OR"...
Vulnerability Description
Tor before 0.1.1.20 uses improper logic to validate the "OR" destination, which allows remote attackers to perform a man-in-the-middle (MITM) attack via unspecified vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3415
Credits & Attribution
No credits recorded in the NVD database.
References
More from tor
View All →CVE-2012-3519
routerlist.c in Tor before 0.2.2.38 uses a different amount of...
Medium
5
CVE-2012-3518
The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does...
Medium
5
CVE-2012-3517
Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow...
Medium
5
CVE-2011-4897
Tor before 0.2.2.25-alpha, when configured as a relay without the...
Medium
4.3
CVE-2011-4896
Tor before 0.2.2.24-alpha continues to use a reachable bridge that...
Medium
4.3
Affected Vendor
Affected Software
tor
Vulnerable Versions:
0.0.2, 0.0.2_pre13, 0.0.2_pre14, 0.0.2_pre15, 0.0.2_pre16, 0.0.2_pre17, 0.0.2_pre18, 0.0.2_pre19, 0.0.2_pre20, 0.0.2_pre21, 0.0.2_pre22, 0.0.2_pre23, 0.0.2_pre24, 0.0.2_pre25, 0.0.2_pre26, 0.0.2_pre27, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.6.1, 0.0.6.2, 0.0.7, 0.0.7.1, 0.0.7.2, 0.0.7.3, 0.0.8, 0.0.8.1, 0.0.9, 0.0.9.1, 0.0.9.2, 0.0.9.3, 0.0.9.4, 0.0.9.5, 0.0.9.6, 0.0.9.7, 0.0.9.8, 0.0.9.9, 0.0.9.10, 0.1.0.1, 0.1.0.2, 0.1.0.3, 0.1.0.4, 0.1.0.5, 0.1.0.6, 0.1.0.7, 0.1.0.8, 0.1.0.9, 0.1.0.10, 0.1.0.11, 0.1.0.12, 0.1.0.13, 0.1.0.14, 0.1.0.15, 0.1.0.16, 0.1.0.17, 0.1.0.18, 0.1.0.19, 0.1.1.1_alpha, 0.1.1.2_alpha, 0.1.1.3_alpha, 0.1.1.4_alpha, 0.1.1.5_alpha, 0.1.1.6_alpha, 0.1.1.7_alpha, 0.1.1.8_alpha, 0.1.1.9_alpha, 0.1.1.10_alpha
Timeline
Official Publish:
July 7th, 2006
Last Modified:
September 17th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.