Re: Fwd: Tor Project Forum: Security Release 0.4.9.12
Tor 0.4.9.12 patches a flaw that lets a malicious guard redirect circuit building to chosen relays undetected.
Sam James highlighted Tor Project security release 0.4.9.12 on the oss-security list. He called out a circuit-building flaw as the most significant issue: a malicious guard can influence which relays a circuit uses, and Tor does not detect the tampering. The post cites no CVE and does not report active exploitation.
- oss-security discussion of Tor security release 0.4.9.12.
- A malicious guard can steer circuits toward relays it chooses.
- Tor does not detect that circuit-building tampering.
Posted by Sam James on Sep 23 Sam James writes: https://gitlab.torproject.org/tpo/core/tor/-/work_items/XXXX. From a quick look, this appears to be the most significant one, as a malicious guard can influence circuit building to relays of its choosing, without the tampering being detected by tor. sam
This source does not provide full text. Read it at seclists.org.