Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 190968 - net-misc/tor < 0.1.2.17 insecure control protocol
Summary: net-misc/tor < 0.1.2.17 insecure control protocol
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://archives.seul.org/or/announce/...
Whiteboard: B3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2007-09-01 15:14 UTC by Gustavo Felisberto (RETIRED)
Modified: 2007-09-25 09:40 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gustavo Felisberto (RETIRED) gentoo-dev 2007-09-01 15:14:54 UTC
The 0.1.2.17 is already in portage.

Older version should be removed after this one is stable.
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2007-09-01 16:54:04 UTC
This is public, no need to restrict the bug.
Comment 2 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-01 21:58:36 UTC
Thanks for the report Gustavo. The advisory isn't very explicit though, it just mentions "important security risks", do you have more details on this?

arches, please test and mark stable net-misc/tor-0.1.2.17.
Target keywords are: "amd64 ppc ppc64 sparc x86 ~x86-fbsd"
Comment 3 Christian Faulhammer (RETIRED) gentoo-dev 2007-09-02 06:51:29 UTC
Sorry guys, 0.1.2.17 is not in Portage.  I bumped it now myself, with stable x86, I hope you don't mind Gustavo, I just copied the ebuild over.
Comment 4 Angelo Arrifano (RETIRED) gentoo-dev 2007-09-02 14:25:43 UTC
net-misc/tor-0.1.2.17

1. Emerges on AMD64
2. No collisions, etc..
3. Browsed some webpages behind tor network using http and dns through socks5.
   Connected to IRC behind tor network.
   All working.. Interesting stuff, way better than anonymous proxies. :)
Comment 5 Christoph Mende (RETIRED) gentoo-dev 2007-09-02 14:49:36 UTC
amd64 stable
Comment 6 Markus Rothe (RETIRED) gentoo-dev 2007-09-02 15:09:39 UTC
ppc64 stable
Comment 7 Gustavo Felisberto (RETIRED) gentoo-dev 2007-09-02 15:49:34 UTC
I forgot to commit the 0.1.2.17 version :(
Cristian: Thanks for bumping it, that was all that was needed.

As far as I can tell the issue solved is related to:

http://archives.seul.org/or/announce/Sep-2007/msg00000.html
Comment 8 Christian Faulhammer (RETIRED) gentoo-dev 2007-09-02 20:47:14 UTC
Security, I think B3 is appropriate here.  As far as I understand, a DoS is possible by sending commands to tor configuration.
Comment 9 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2007-09-02 21:00:26 UTC
stable on sparc.
Comment 10 Tobias Scherbaum (RETIRED) gentoo-dev 2007-09-03 18:10:22 UTC
ppc stable
Comment 11 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-08 12:24:04 UTC
(In reply to comment #8)
> Security, I think B3 is appropriate here.  As far as I understand, a DoS is
> possible by sending commands to tor configuration.
> 
Right. I tend to vote yes.
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2007-09-09 19:07:29 UTC
I tend to vote NO.
Comment 13 Matt Drew (RETIRED) gentoo-dev 2007-09-09 22:49:57 UTC
hmm, user-assisted, but only a compromise to the privacy of the user.  I think this qualifies as a bug rather than a security issue.  I vote no.
Comment 14 Pierre-Yves Rofes (RETIRED) gentoo-dev 2007-09-25 09:40:41 UTC
finally changing my vote to NO and closing without glsa.