CVE-2008-5398
EPSS 0.84%Published: 12/9/2008Modified: 4/28/2026
Description
Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the destination hostname of a refused stream.
Affected packages (1)
- Debian/torfrom 0, < 0.2.0.32-1