Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is not forward secure: eavesdroppers can decrypt network traffic between two accounts if they later compromise both accounts. NOTE: the eavesdropping is typically impractical because BHP runs over an encrypted session that uses the Tor hidden service protocol.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-38106 Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is not forward secure: eavesdroppers can decrypt network traffic between two accounts if they later compromise both accounts. NOTE: the eavesdropping is typically impractical because BHP runs over an encrypted session that uses the Tor hidden service protocol.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 16 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-01-16T15:48:49.894Z

Reserved: 2023-05-24T00:00:00

Link: CVE-2023-33982

cve-icon Vulnrichment

Updated: 2024-08-02T15:54:14.203Z

cve-icon NVD

Status : Modified

Published: 2023-05-24T18:15:10.927

Modified: 2025-01-16T16:15:30.683

Link: CVE-2023-33982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.