AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-5397

HIGH · CVSS 7.2 EPSS 0.36%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-12-09 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2008-5397
Severity
HIGH
CVSS
7.2
EPSS
0.36%

Original NVD Description

Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.