CVE-2017-16541
Dashboard / Vulnerabilities / CVE-2017-16541
CVE-2017-16541
Summary:
Details: Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.
References: http://www.securitytracker.com/id/1041610, http://www.securityfocus.com/bid/101665, https://access.redhat.com/errata/RHSA-2018:3403, https://security.gentoo.org/glsa/201811-13, https://www.debian.org/security/2018/dsa-4327, https://access.redhat.com/errata/RHSA-2018:2693, https://lists.debian.org/debian-lts-announce/2018/11/msg00011.html, https://security.gentoo.org/glsa/201810-01, https://access.redhat.com/errata/RHSA-2018:3458, https://access.redhat.com/errata/RHSA-2018:2692, https://trac.torproject.org/projects/tor/ticket/24052, https://blog.torproject.org/tor-browser-709-released, https://bugzilla.mozilla.org/show_bug.cgi?id=1412081, https://www.bleepingcomputer.com/news/security/tormoil-vulnerability-leaks-real-ip-address-from-tor-browser-users/, https://www.wearesegment.com/research/tormoil-torbrowser-unspecified-critical-security-vulnerability/
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
