[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #21278 [Core Tor/Tor]: Avoid signed integer underflow when comparing versions (Fix TROVE-2017-001)



#21278: Avoid signed integer underflow when comparing versions (Fix TROVE-2017-001)
--------------------------+------------------------------------
 Reporter:  nickm         |          Owner:  nickm
     Type:  defect        |         Status:  needs_revision
 Priority:  Medium        |      Milestone:  Tor: 0.3.0.x-final
Component:  Core Tor/Tor  |        Version:
 Severity:  Normal        |     Resolution:
 Keywords:  029-backport  |  Actual Points:
Parent ID:                |         Points:
 Reviewer:                |        Sponsor:
--------------------------+------------------------------------

Comment (by nickm):

 > Am I remembering correctly that only recent Tor branches have put
 expensive-hardening on by default? That is, the earlier fix for this TROVE
 (i.e. disabling ftrapv) only went into 0.2.9.x and 0.3.0.x?

 This bug affects everybody who has trapv or ubsan turned on.  In
 0.2.9.1-alpha, we turned trapv on by default, which caused this bug to
 affect 0.2.9.1-alpha through 0.2.9.8.

 This bug will still affect all older versions if they have --enable-
 expensive-hardening turned on.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/21278#comment:10>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs