tor 0.2.3.23-rc-1 source package in Debian

Changelog

tor (0.2.3.23-rc-1) unstable; urgency=low


  * New upstream version:
    o Major bugfixes (security/privacy):
      - Disable TLS session tickets. OpenSSL's implementation was giving
        our TLS session keys the lifetime of our TLS context objects, when
        perfect forward secrecy would want us to discard anything that
        could decrypt a link connection as soon as the link connection
        was closed. Fixes bug 7139; bugfix on all versions of Tor linked
        against OpenSSL 1.0.0 or later. Found by Florent Daignière.
      - Discard extraneous renegotiation attempts once the V3 link
        protocol has been initiated. Failure to do so left us open to
        a remotely triggerable assertion failure. Fixes CVE-2012-2249;
        bugfix on 0.2.3.6-alpha. Reported by "some guy from France".
      - Fix a possible crash bug when checking for deactivated circuits
        in connection_or_flush_from_first_active_circuit(). Fixes bug 6341;
        bugfix on 0.2.2.7-alpha. Bug report and fix received pseudonymously.
    For other fixes please see the upstream changelog.

 -- Peter Palfrader <email address hidden>  Sat, 20 Oct 2012 22:27:04 +0200

Upload details

Uploaded by:
Peter Palfrader
Uploaded to:
Sid
Original maintainer:
Peter Palfrader
Architectures:
any all
Section:
net
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
tor_0.2.3.23-rc-1.dsc 1.6 KiB 327939cc5bf297e3f2be0e6144afb25f7345c972e1adfe1de3a18f99da808701
tor_0.2.3.23-rc.orig.tar.gz 3.0 MiB 090e3b932b84629a2f5f0ef1a2801d9e9e4c50cf288321d9b861a6cd8037a198
tor_0.2.3.23-rc-1.diff.gz 33.4 KiB ccff62457151587285c7f3964924f80f36814ae25e1a1c851b4cd4ee2caad912

No changes file available.

Binary packages built by this source