{"id":"CVE-2017-0377","details":"Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties by leveraging the existence of large families.","modified":"2026-05-17T12:01:13.482909207Z","published":"2017-07-02T15:29:00.187Z","related":["openSUSE-SU-2024:11469-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:torproject:tor:0.3.0.1:alpha:*:*:*:*:*:*","cpe:2.3:a:torproject:tor:0.3.0.4:*:*:*:*:*:*:*","cpe:2.3:a:torproject:tor:0.3.0.5:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"0.3.0.1-alpha"},{"last_affected":"0.3.0.4"},{"last_affected":"0.3.0.4"},{"last_affected":"0.3.0.5"},{"last_affected":"0.3.0.5"}],"source":"CPE_FIELD","vendor_product":"torproject:tor"}]},"references":[{"type":"ADVISORY","url":"https://blog.torproject.org/blog/tor-0309-released-security-update-clients"},{"type":"ADVISORY","url":"https://blog.torproject.org/blog/tor-0314-alpha-released-security-update-clients"},{"type":"ADVISORY","url":"https://security-tracker.debian.org/CVE-2017-0377"},{"type":"REPORT","url":"https://trac.torproject.org/projects/tor/ticket/22753"},{"type":"FIX","url":"https://github.com/torproject/tor/commit/665baf5ed5c6186d973c46cdea165c0548027350"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}