{"id":"MGASA-2014-0059","summary":"Updated tor package fixes security vulnerability","details":"Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a\ncertain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge\nplatforms, does not properly generate random numbers for relay identity\nkeys and hidden-service identity keys, which might make it easier for\nremote attackers to bypass cryptographic protection mechanisms via\nunspecified vectors (CVE-2013-7295).\n","modified":"2026-04-16T06:24:23.169839795Z","published":"2014-02-12T17:13:24Z","upstream":["CVE-2013-7295"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0059.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=12464"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2014-01/msg00095.html"}],"affected":[{"package":{"name":"tor","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/tor?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.4.20-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0059.json"}},{"package":{"name":"tor","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/tor?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.4.20-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0059.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}