Please update Tor in older versions of Ubuntu

Bug #697407 reported by Runa A. Sandvik
290
This bug affects 6 people
Affects Status Importance Assigned to Milestone
tor (Ubuntu)
Fix Released
Undecided
Jacob Appelbaum
Hardy
Won't Fix
Undecided
Unassigned

Bug Description

Binary package hint: tor

Dapper, Dapper-updates, Hardy and Hardy-updates are currently shipping old versions of Tor.

CVE References

Gary M (garym)
tags: added: dapper hardy upgrade
Revision history for this message
Jacob Appelbaum (jacob-appelbaum) wrote :

It probably makes sense to use the packages we have on deb.torproject.org; are we cleared to push those even though they're radically different versions?

Changed in tor (Ubuntu):
assignee: nobody → Jacob Appelbaum (jacob-appelbaum)
Revision history for this message
Krzysztof Klimonda (kklimonda) wrote :

I believe tor still has an exception for SRU so we should be able to update it the way we do with clamav. We could just backport the package we already have in natty (it's synced from debian directly). I don't think it makes sense to backport it to dapper, as it's already near EOL, but there should be nothing stopping us from pushing it to hardy-updates. If it's okay with you Jason, I could do that tomorrow or the day after.

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in tor (Ubuntu):
status: New → Confirmed
Revision history for this message
Jacob Appelbaum (jacob-appelbaum) wrote :

What needs to be done to push this bug forward?

Changed in tor (Ubuntu Hardy):
status: New → Confirmed
Revision history for this message
Kenyon Ralph (kralph) wrote :

There are security issues with the version of tor in the current Ubuntu release (oneiric). Debian has packaged an update: http://packages.qa.debian.org/t/tor/news/20111028T200707Z.html

It would be nice to get this in Ubuntu.

tags: added: security
security vulnerability: no → yes
Revision history for this message
pioruns (pioruns) wrote :

@kralph:
Absolutely right.

Tor from Oneiric warn us:

[warn] Please upgrade! This version of Tor (0.2.1.30) is obsolete, according to the directory authorities. Recommended versions are: 0.2.1.31,0.2.2.34,0.2.3.6-alpha

There are security issues it this version and Tor should be upgraded as soon as possible.

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug and helping to make Ubuntu better. The package referred to in this bug is in universe or multiverse and reported against a release of Ubuntu (hardy) which no longer receives updates outside of the explicitly supported LTS packages. While the bug against hardy is being marked "Won't Fix" for now, if you are interested feel free to post a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures'

Please feel free to report any other bugs you may find.

Changed in tor (Ubuntu Hardy):
status: Confirmed → Won't Fix
Changed in tor (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.