Security

NAVIGATION
CATEGORIES
REFERRENCE
LINKS
  • ScatterChat Advisory 2006-02: Win32 Tor ClientRouting and Denial of Service Vulnerabilitie

    0 answers - 1836 bytes - related search similar search Add To My Delicious Add To My Stumble Upon Add To My Google Mark Add To My Facebook Add To My Digg Add To My Reddit

    PGP SIGNED MESSAGE
    Hash: SHA1
    ScatterChat Advisory 2006-02: Win32 Tor Client Routing and Denial of
    Service Vulnerabilities
    Technical Report
    September 2nd, 2006
    CVE ID: CVE-2006-4508
    SVDB: 28276, 28277
    SUMMARY
    ScatterChat (http://www.scatterchat.com/) is an instant messaging project
    that aims to provide encryption and anonymity support with Tor to
    non-technical users such as human rights activists and political
    dissidents.
    Vulnerabilities were found in the external Tor program that is packaged
    with the Windows installer. This vulnerability allows a Tor entry node
    to route traffic through the client, or to cause a denial of service by
    crashing the Tor process with malformed input.
    The impact of this vulnerability is low.
    DETAILS
    The official Tor advisory can be found at:
    IMPACT
    The end-user impact of this issue is low.
    Should a malicious or compromised Tor entry node successfully exploit
    these issues, the local user's Tor process would crash, and/or the user's
    machine would route traffic to other Tor nodes.
    Routing unwanted traffic would cause bandwidth resources to be consumed
    as long as ScatterChat is running.
    SLUTIN
    All Windows users who employ ScatterChat's anonymity feature are
    strongly encouraged to upgrade to ScatterChat v1.0.2:
    CNTACT
    J. Salvatore Testa II
    jtesta
    3428 E58E 715E C37D 2AA7 C55E 97D1 DE8C 4B26 2B62
    - -
    A less technical summary of this advisory can be found at:
    PGP SIGNATURE
    Version: GnuPG v1.4.5 (GNU/Linux)
    qtJQVqTJoHgbb/vXCv0+sQo=
    =mw1y
    PGP SIGNATURE
    Full-Disclosure - We believe in it.
    Charter:
    Hosted and sponsored by Secunia - http://secunia.com/

Re: ScatterChat Advisory 2006-02: Win32 Tor ClientRouting and Denial of Service Vulnerabilitie


max 4000 letters.
Your nickname that display:
In order to stop the spam: 0 + 9 =
QUESTION ON "Security"

EMSDN.COM