[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Tor Browser 7.0.8 IP Address Leak Vulnerability

Author
Filippo Cavallarin
Risk
[
Security Risk High
]
0day-ID
0day-ID-28954
Category
remote exploits
Date add
05-11-2017
Platform
multiple
Title: TorMoil: TorBrowser unspecified critical security vulnerability
Product: Tor Browser
Version: 7.0.8 and probably prior
Vendor: torproject.org
Vulnerability type:  Unspecified
Risk level:  5 / 5
Credit:  Filippo Cavallarin - wearesegment.com
CVE: N / A

Details

TorBrowser version 7.0.8, and probably prior,for Mac OS X and Linux, is affected
by a critical security issue. According to the Tor Project, further details will
be released in the near future.

Due to a Firefox bug in handling file:// URLs it is possible on both systems that
users leak their IP address. Once an affected user navigates to a specially crafted
web page, the operating system may directly connect to the remote host,
bypassing Tor Browser.

Users are strongly advised to keep their TorBrowser updated.

We named this vulnerability TorMoil.

Solution

Update TorBrowser to version 7.0.9


References

https://www.torproject.org/
https://www.wearesegment.com/research/tormoil-torbrowser-unspecified-critical-security-vulnerability/
https://www.wearesegment.com/news/the-tormoil-bug-torbrowser-critical-security-vulnerability/

#  0day.today [2024-11-15]  #