CVE-2008-5397

NameCVE-2008-5397
DescriptionTor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh
Debian Bugs505178

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tor (PTS)stretch0.2.9.16-1fixed
stretch (security)0.2.9.15-1fixed
buster, buster (security)0.3.5.14-1fixed
bullseye, sid0.4.5.7-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
torsource(unstable)0.2.0.32-1505178

Search for package or bug name: Reporting problems