HIGH
Tor Browser Launcher (aka torbrowser-launcher) before 0.2.4, during the initial run, allows man-in-the-middle attackers to bypass the PGP signature verification and execute arbitrary code via a Trojan horse tar file and a signature file with the valid tarball and signature
Published Feb 7, 2017
8.1
HIGHCVSS 3.0
EPSS 1.92%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.