VYPR
Unrated severityNVD Advisory· Published Aug 23, 2005· Updated Jun 16, 2026

CVE-2005-2643

CVE-2005-2643

Description

Tor 0.1.0.13 and earlier, and experimental versions 0.1.1.4-alpha and earlier, does not reject certain weak keys when using ephemeral Diffie-Hellman (DH) handshakes, which allows malicious Tor servers to obtain the keys that a client uses for other systems in the circuit.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

28
  • Tor/Tor28 versions
    cpe:2.3:a:tor:tor:0.0.9.1:*:*:*:*:*:*:*+ 27 more
    • cpe:2.3:a:tor:tor:0.0.9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.0.9.2:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.0.9.3:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.0.9.4:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.0.9.5:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.0.9.6:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.0.9.7:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.0.9.8:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.0.9.9:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.12:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.1.1_alpha:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.1.2_alpha:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.1.3_alpha:*:*:*:*:*:*:*
    • cpe:2.3:a:tor:tor:0.1.1.4_alpha:*:*:*:*:*:*:*
    • (no CPE)range: <=0.1.0.13, <=0.1.1.4-alpha

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.