Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 739582 - [youbroketheinternet] www-client/torbrowser: Outdated and vulnerable
Summary: [youbroketheinternet] www-client/torbrowser: Outdated and vulnerable
Status: CONFIRMED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Overlays (show other bugs)
Hardware: All Linux
: Normal major
Assignee: lynX
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-08-30 00:41 UTC by John Helmert III
Modified: 2022-11-22 06:37 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-08-30 00:41:07 UTC
The latest version of torbrowser in the overlay is 60.2.1_p802, the earliest is 31.7.0_p451. The latest version of torbrowser is based on Firefox 68.12.0. There are numerous vulnerabilities in Firefox+plugins+torbrowser that all versions of torbrowser in this overlay are vulnerable to. Please update and cleanup old, vulnerable versions.

This is a package that is uniquely expected to be kept secure and up to date, and many users of it will expect this. Please be mindful of this.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-01-27 17:01:23 UTC
The situation doesn't seem to have changed. Tor Browser 10.0.9 was released today, and the latest version in this repository appears to correspond to 9.5.4.
Comment 2 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2021-01-27 18:54:21 UTC
I can't find Tor Browser release history on the webpage.  Could you point me to it?  TB has apparently been bumped since this report was filed.
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-01-27 19:49:17 UTC
It's been bumped, but still lagging behind upstream significantly:

https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/blob/master/projects/tor-browser/Bundle-Data/Docs/ChangeLog.txt
Comment 4 poncho 2021-02-10 23:33:09 UTC
They copy the ebuild from the torbrowser overlay available at
https://github.com/MeisterP/torbrowser-overlay
and https://0xacab.org/poncho/torbrowser-overlay

You're welcome to add the torbrowser overlay directly. It's available in layman as well.
I usually bump the version withing a few days.


(In reply to Michał Górny from comment #2)
> I can't find Tor Browser release history on the webpage.  Could you point me
> to it?  TB has apparently been bumped since this report was filed.

I recommend to follow https://blog.torproject.org/category/tags/tor-browser to get notified about new releases.
Comment 5 Vitaly Zdanevich 2022-03-06 00:13:06 UTC
In this new world in Russia - bypassing a blocked internet is more important, please return Tor browser into main tree.
Comment 6 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-06 00:20:30 UTC
(In reply to Vitaly Zdanevich from comment #5)
> In this new world in Russia - bypassing a blocked internet is more
> important, please return Tor browser into main tree.

There are ways to use it outside of Portage. It's been almost a decade since it was dropped from ::gentoo.