From https://blog.torproject.org/arti_115_released/: "Finally, this release also fixes a security issue: there was a bug in our SOCKS code that could be exploited to cause a denial-of-service attack against an Arti client. We are classifying this as a low-severity issue, since exploiting it would require the attacker to have access to localhost. Thanks to Jakob Lell for reporting this issue; it is tracked as TROVE-2023-001."
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=0cb439ed1425c7e27f9081199493bd07bea3a54a commit 0cb439ed1425c7e27f9081199493bd07bea3a54a Author: John Helmert III <ajak@gentoo.org> AuthorDate: 2023-06-03 18:16:24 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2023-06-03 18:21:06 +0000 net-p2p/arti: drop 1.1.1, 1.1.3 Bug: https://bugs.gentoo.org/907779 Signed-off-by: John Helmert III <ajak@gentoo.org> net-p2p/arti/Manifest | 207 ----------------- net-p2p/arti/arti-1.1.1.ebuild | 480 ---------------------------------------- net-p2p/arti/arti-1.1.3.ebuild | 490 ----------------------------------------- 3 files changed, 1177 deletions(-) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=a2eab5d8a75386f420ee3d2eb4c5369a4d4621a6 commit a2eab5d8a75386f420ee3d2eb4c5369a4d4621a6 Author: John Helmert III <ajak@gentoo.org> AuthorDate: 2023-06-03 18:16:02 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2023-06-03 18:21:06 +0000 net-p2p/arti: add 1.1.5 Bug: https://bugs.gentoo.org/907779 Signed-off-by: John Helmert III <ajak@gentoo.org> net-p2p/arti/Manifest | 97 ++++++++ net-p2p/arti/arti-1.1.5.ebuild | 504 +++++++++++++++++++++++++++++++++++++++++ 2 files changed, 601 insertions(+)
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=ad45ab74e6340e508b7da4a74b177498c93fa0cf commit ad45ab74e6340e508b7da4a74b177498c93fa0cf Author: John Helmert III <ajak@gentoo.org> AuthorDate: 2023-06-11 18:59:24 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2023-06-11 19:00:05 +0000 net-p2p/arti: drop 1.1.4 Bug: https://bugs.gentoo.org/907779 Signed-off-by: John Helmert III <ajak@gentoo.org> net-p2p/arti/Manifest | 99 -------- net-p2p/arti/arti-1.1.4.ebuild | 506 ----------------------------------------- 2 files changed, 605 deletions(-)
All unstable, all done.