Related Vulnerabilities: CVE-2017-8822  

In Tor before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.

Severity High

Remote Yes

Type Information disclosure

Description

In Tor before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.

AVG-539 tor 0.3.1.8-1 0.3.1.9-1 High Fixed

16 Dec 2017 ASA-201712-10 AVG-539 tor High multiple issues

https://bugs.torproject.org/21534
https://bugs.torproject.org/24333