First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 256078
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Stefan Behte <craig@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 256078 depends on: Show dependency tree
Bug 256078 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2009-01-23 11:55 0000
Security fixes:
    * Fix a heap-corruption bug that may be remotely triggerable on
      some platforms. Reported by Ilja van Sprundel.

------- Comment #1 From Stefan Behte 2009-01-23 11:57:38 0000 -------
I don't know, if we're one of those platforms, thus rating B1?

------- Comment #2 From Christian Faulhammer 2009-01-24 09:30:55 0000 -------
Normally I wanted to ask arches to mark 2.0.32-r1 stable today...but we will do
with a different version. :)

Ebuild in the tree, arches please mark net-misc/tor-2.0.33 stable.

------- Comment #3 From Brent Baude 2009-01-24 18:13:44 0000 -------
ppc64 done

------- Comment #4 From Ferris McCormick 2009-01-24 18:31:05 0000 -------
Sparc stable.

------- Comment #5 From Tobias Scherbaum 2009-01-24 18:41:06 0000 -------
ppc stable

------- Comment #6 From Markus Meier 2009-01-25 13:56:12 0000 -------
amd64/x86 stable, all arches done.

------- Comment #7 From Stefan Behte 2009-01-25 14:42:44 0000 -------
glsa request filed, if we're not affected, the request will be withdrawn.

------- Comment #8 From Christian Faulhammer 2009-01-26 22:49:43 0000 -------
All vulnerable versions removed, we still have bug 250018 open.

------- Comment #9 From Christian Faulhammer 2009-02-08 22:30:01 0000 -------
(In reply to comment #7)
> glsa request filed, if we're not affected, the request will be withdrawn.

 Any new information if we are affected

------- Comment #10 From Robert Buchholz 2009-02-08 23:58:05 0000 -------
Not as far as I have seen, no :-/

------- Comment #11 From Jesse Adelman 2009-02-12 22:36:39 0000 -------
Hrm, since this bug is still open, here's a new security fix for Tor, 0.2.0.34.

https://blog.torproject.org/blog/tor-0.2.0.34-stable-released

Yep, I searched for another bug, but searching for "tor" in bugzilla, well, it
doesn't exactly narrow the results. Apologies if another bug exists. :)

------- Comment #12 From Robert Buchholz 2009-02-13 17:02:25 0000 -------
(In reply to comment #11)
> Hrm, since this bug is still open, here's a new security fix for Tor, 0.2.0.34.
> 
> https://blog.torproject.org/blog/tor-0.2.0.34-stable-released
> 
> Yep, I searched for another bug, but searching for "tor" in bugzilla, well, it
> doesn't exactly narrow the results. Apologies if another bug exists. :)

It does now, bug 258833.

------- Comment #13 From svrmarty 2009-02-15 13:21:22 0000 -------
higher version needed,

see bug #258833

------- Comment #14 From Robert Buchholz 2009-04-08 22:49:29 0000 -------
GLSA 200904-11

First Last Prev Next    No search results available      Search page      Enter new bug