Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 186644 - net-misc/tor < 0.1.2.16 multiple vulnerabilities (CVE-2007-409[6789])
Summary: net-misc/tor < 0.1.2.16 multiple vulnerabilities (CVE-2007-409[6789])
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/26140/
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-07-26 06:21 UTC by Christian Faulhammer (RETIRED)
Modified: 2007-08-11 06:48 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christian Faulhammer (RETIRED) gentoo-dev 2007-07-26 06:21:21 UTC
o Major bugfixes (security):
    - Fix a possible buffer overrun when using BSD natd support. Bug
      found by croup.
    - When sending destroy cells from a circuit's origin, don't include
      the reason for tearing down the circuit. The spec says we didn't,
      and now we actually don't. Reported by lodger.
    - Keep streamids from different exits on a circuit separate. This
      bug may have allowed other routers on a given circuit to inject
      cells into streams. Reported by lodger; fixes bug 446.
    - If there's a never-before-connected-to guard node in our list,
      never choose any guards past it. This way we don't expand our
      guard list unless we need to.
Comment 1 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-02 14:14:46 UTC
Setting status. Humpback, please advise and bump as necessary.
Comment 2 Patrick 2007-08-03 01:41:19 UTC
Additional information for tor 0.1.2.16:

Changes in version 0.1.2.16 - 2007-08-01
  o Major security fixes:
    - Close immediately after missing authentication on control port;
      do not allow multiple authentication attempts.
Comment 3 Christian Faulhammer (RETIRED) gentoo-dev 2007-08-03 05:45:18 UTC
If humpback does not react until monday, I will bump.  Sorry, am off for the weekend.
Comment 4 Christian Faulhammer (RETIRED) gentoo-dev 2007-08-03 11:39:18 UTC
Ok, I bumped it as I my departure has been delayed.  It works fine here locally, but arch teams can test more...have fun, I cc.  Security, I hope you don't feel stepped on your toes.
Comment 5 Christian Faulhammer (RETIRED) gentoo-dev 2007-08-03 13:50:12 UTC
"Sorry, we will be later to pick you up."  So my weekend holiday is delayed even more.  Your luck.  So I can test more. 

x86 stable
Comment 6 Tobias Scherbaum (RETIRED) gentoo-dev 2007-08-04 10:24:47 UTC
ppc stable
Comment 7 Markus Rothe (RETIRED) gentoo-dev 2007-08-04 14:56:04 UTC
ppc64 stable
Comment 8 Gustavo Zacarias (RETIRED) gentoo-dev 2007-08-06 14:08:12 UTC
sparc stable.
Comment 9 Robert Buchholz (RETIRED) gentoo-dev 2007-08-09 17:42:22 UTC
amd64 stable (last arch)
Comment 10 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-08-09 17:54:14 UTC
This one is ready for glsa decision. Since the natd issue seems to be restricted to *BSD, I vote NO.
Comment 11 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-08-11 06:48:07 UTC
Voting NO and closing. Feel free to reopen if you disagree.