Format: 1.8 Date: Fri, 23 Nov 2018 14:25:06 -0200 Source: tor Binary: tor tor-dbg tor-geoipdb Architecture: powerpc Version: 0.2.4.27-1ubuntu0.1 Distribution: trusty Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Eduardo Barretto Description: tor - anonymizing overlay network for TCP tor-dbg - debugging symbols for Tor tor-geoipdb - GeoIP database for Tor Changes: tor (0.2.4.27-1ubuntu0.1) trusty-security; urgency=medium . * SECURITY UPDATE: DoS (client crash) via a crafted hidden service descriptor. - debian/patches/CVE-2016-1254.patch: Fix parsing bug with unrecognized token at EOS. - CVE-2016-1254 * SECURITY UPDATE: DoS (crash) via crafted data. - debian/patches/CVE-2016-8860.patch: Protect against NUL-terminated inputs. - CVE-2016-8860 * SECURITY UPDATE: DoS (assertion failure and daemon exit) via a BEGIN_DIR rendezvous circuit. - debian/patches/CVE-2017-0376.patch: Fix assertion failure. - CVE-2017-0376 * SECURITY UPDATE: Replay-cache protection mechanism is ineffective for v2 onion services. - debian/patches/CVE-2017-8819.patch: Fix length of replaycache-checked data. - CVE-2017-8819 * SECURITY UPDATE: DoS (application hang) via a crafted PEM input. - debian/patches/CVE-2017-8821.patch: Avoid asking for passphrase on junky PEM input. - CVE-2017-8821 * SECURITY UPDATE: Relays, that have incompletely downloaded descriptors, can pick themselves in a circuit path, leading to a degradation of anonymity - debian/patches/CVE-2017-8822.patch: Use local descriptor object to exclude self in path selection. - CVE-2017-8822 Checksums-Sha1: 2f729bfa937cc13fd2c7d4a1517c026618ee7c1b 656266 tor_0.2.4.27-1ubuntu0.1_powerpc.deb 4584aeee3107ae445c382ae58dd31342ca1260b6 1404564 tor-dbg_0.2.4.27-1ubuntu0.1_powerpc.deb cdf3877ab43c542970d918b0d8763af9e9edf63b 1558 tor-dbgsym_0.2.4.27-1ubuntu0.1_powerpc.ddeb Checksums-Sha256: ad21a1abf36e116acfc21586baa3bd7641df8ded0a5321c21ab2f856d05b8b0a 656266 tor_0.2.4.27-1ubuntu0.1_powerpc.deb 714f8d567f0afa4a5417815a98ccf75ede0bd6afb6ddffda7e3408231226c284 1404564 tor-dbg_0.2.4.27-1ubuntu0.1_powerpc.deb cbe3e64168e43888d0eb107523bc3c9aa5050597b1c61f427f1a80e0ceb8d43d 1558 tor-dbgsym_0.2.4.27-1ubuntu0.1_powerpc.ddeb Files: d47e5216d54f026848c0b8e3cfc92e79 656266 net optional tor_0.2.4.27-1ubuntu0.1_powerpc.deb 681ca5a960ed16fc96f394699731fe39 1404564 debug extra tor-dbg_0.2.4.27-1ubuntu0.1_powerpc.deb 7b202eb854116ec4d590659b5beb6e8d 1558 net extra tor-dbgsym_0.2.4.27-1ubuntu0.1_powerpc.ddeb Original-Maintainer: Peter Palfrader