High severity8.1NVD Advisory· Published Feb 7, 2017· Updated May 13, 2026
CVE-2016-3180
CVE-2016-3180
Description
Tor Browser Launcher (aka torbrowser-launcher) before 0.2.4, during the initial run, allows man-in-the-middle attackers to bypass the PGP signature verification and execute arbitrary code via a Trojan horse tar file and a signature file with the valid tarball and signature.
Affected products
1- cpe:2.3:a:tor_browser_launcher_project:tor_browser_launcher:0.2.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/96140nvdThird Party AdvisoryVDB Entry
- github.com/micahflee/torbrowser-launcher/issues/229nvdVendor Advisory
News mentions
0No linked articles in our index yet.