漏洞标题
N/A
漏洞描述信息
Tor允许远程攻击者通过以高速度访问该服务来发现隐藏服务的IP地址,从而改变服务器的CPU温度,相应地改变通过(1)ICMP时间戳、(2)TCP序列号和(3)TCP时间戳可看到的时间值的模式,与CVE-2006-0414不同的漏洞。注意:有人认为这是物理学定律漏洞,某些硬件实现的基本设计限制,所以也许这个问题不应该包含在CVE中。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Tor allows remote attackers to discover the IP address of a hidden service by accessing this service at a high rate, thereby changing the server's CPU temperature and consequently changing the pattern of time values visible through (1) ICMP timestamps, (2) TCP sequence numbers, and (3) TCP timestamps, a different vulnerability than CVE-2006-0414. NOTE: it could be argued that this is a laws-of-physics vulnerability that is a fundamental design limitation of certain hardware implementations, so perhaps this issue should not be included in CVE.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Tor 高速率访问隐藏服务漏洞
漏洞描述信息
Tor 远程攻击者以高速率访问隐藏服务,由此变更服务器CPU温度并随后变更通过(1)ICMP时间戳,(2)TCP序列号和(3)TCP时间戳可见的时间值的模式,来发现此隐藏服务的IP地址。
CVSS信息
N/A
漏洞类别
授权问题