CVE-2017-0380 is a medium-severity information disclosure vulnerability affecting Tor versions prior to 0.2.8.15, 0.2.9.12, 0.3.0.11, 0.3.1.7, and 0.3.2.1-alpha. When SafeLogging is disabled, attackers with access to a hidden service's log files can obtain sensitive information due to uninitialized stack data being included in an error message. The vulnerability has a CVSSv3 score of 5.9, indicating a network-based attack with high confidentiality impact but high attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.2.8.14CPE matchmatch criteria | cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:* | ||
0.2.9.0CPE matchmatch criteria | cpe:2.3:a:torproject:tor:0.2.9.0:*:*:*:*:*:*:* | ||
0.2.9.0CPE matchmatch criteria | cpe:2.3:a:torproject:tor:0.2.9.0:alpha:*:*:*:*:*:* | ||
0.2.9.1CPE matchmatch criteria | cpe:2.3:a:torproject:tor:0.2.9.1:alpha:*:*:*:*:*:* | ||
0.2.9.2CPE matchmatch criteria | cpe:2.3:a:torproject:tor:0.2.9.2:alpha:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.