• icegladiator@lemy.lol
    link
    fedilink
    English
    arrow-up
    1
    ·
    12 hours ago

    i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 and IPv6 addresses that occurs when a tunneled, replayed message has a behavior discrepancy (it may be dropped, or may result in a Wrong Destination response). https://nvd.nist.gov/vuln/detail/CVE-2023-36325