CVE-2023-36325

NameCVE-2023-36325
DescriptionAttackers can de-anonymize i2p hidden services with a message replay attack
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1043161

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
i2p (PTS)buster0.9.38-3.1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
i2psource(unstable)(unfixed)1043161

Notes

https://xeiaso.net/blog/CVE-2023-36325
https://geti2p.net/en/blog/post/2023/06/25/new_release_2.3.0
https://i2pgit.org/i2p-hackers/i2p.i2p/-/commit/82aa4e19fbb37ca1bd752ec1b836120beec0985f (i2p-2.3.0)

Search for package or bug name: Reporting problems