First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 96320
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Gustavo Felisberto <humpback@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 96320 depends on: Show dependency tree
Bug 96320 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-06-16 16:12 0000
I just received this from upstream:

Hi folks,

The Tor 0.1.0.10 release from a few days ago includes a fix for a bug
that might allow an attacker to read arbitrary memory (maybe even keys)
from an exit server's process space. We haven't heard any reports of
exploits yet, but hey.

So, I recommend that you all upgrade to 0.1.0.10.  :) 

If you absolutely cannot upgrade yet (for example if you're the Debian Tor
packager and your distribution is too stubborn to upgrade past libevent
1.0b, which has known crash bugs), I've included a patched tarball for
the old 0.0.9 series at:
http://tor.eff.org/dist/tor-0.0.9.10.tar.gz
http://tor.eff.org/dist/tor-0.0.9.10.tar.gz.asc

--Roger

I'm working on the ebuild for the patched version and will be comitting it soon as stable. When it is in the tree i'll post here so that a GLSA may be issued.

------- Comment #1 From Gustavo Felisberto 2005-06-16 16:23:25 0000 -------
Version in portage fixed.
Current keywords:
KEYWORDS="x86 ~ppc ~amd64 ~ppc64 ~sparc"

As x86 was the only version with a packaged marked as stable i dont know what
the other arches must do.

------- Comment #2 From Sune Kloppenborg Jeppesen 2005-06-16 22:20:54 0000 -------
Thx Gustavo, this one is ready for GLSA decision. 

------- Comment #3 From Thierry Carrez (RETIRED) 2005-06-17 02:51:58 0000 -------
Given the security nature of Tor, I tend to vote yes (make that half a yes).
Gustavo: any hint whether this is public ? Can we disclose it ?

------- Comment #4 From Sune Kloppenborg Jeppesen 2005-06-17 03:51:23 0000 -------

    

------- Comment #5 From Sune Kloppenborg Jeppesen 2005-06-17 03:51:23 0000 -------
½ YES 

------- Comment #6 From Sune Kloppenborg Jeppesen 2005-06-17 03:56:04 0000 -------
*** Bug 96359 has been marked as a duplicate of this bug. ***

------- Comment #7 From Sune Kloppenborg Jeppesen 2005-06-17 03:56:19 0000 -------
Opening 

------- Comment #8 From Gustavo Felisberto 2005-06-17 04:05:15 0000 -------
http://archives.seul.org/or/announce/Jun-2005/msg00001.html

It is a public available list so i think yes we can disclose it.

------- Comment #9 From Matthias Geerdsen 2005-06-20 00:50:49 0000 -------
I would also give a half vote for yes, but I'll make it a full yes so that we
get a result ;-)

------- Comment #10 From Matthias Geerdsen 2005-06-20 02:42:52 0000 -------
Looks like other arches had stable versions before...

ppc and ppc64, pls test 0.0.9.10 and mark stable if possible
macos and ppc-macos, you had a stable version quite a while ago, pls have a look
at 0.0.9.10 too

------- Comment #11 From Markus Rothe 2005-06-20 23:04:35 0000 -------
stable on ppc64 

------- Comment #12 From Michael Hanselmann (hansmi) (RETIRED) 2005-06-20 23:30:03 0000 -------
Stable on ppc.

------- Comment #13 From Thierry Carrez (RETIRED) 2005-06-21 13:22:29 0000 -------
GLSA 200406-18
ppc-macos: please test and mark stable to benefit from GLSA

First Last Prev Next    No search results available      Search page      Enter new bug