[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #20384 [Core Tor/Tor]: TROVE-2016-10-001: out-of-bounds read on buffer chunks (was: TROVE-2016-10-001)
#20384: TROVE-2016-10-001: out-of-bounds read on buffer chunks
--------------------------+------------------------------------
Reporter: nickm | Owner:
Type: defect | Status: closed
Priority: Very High | Milestone: Tor: 0.2.9.x-final
Component: Core Tor/Tor | Version:
Severity: Normal | Resolution: fixed
Keywords: | Actual Points:
Parent ID: | Points:
Reviewer: | Sponsor:
--------------------------+------------------------------------
Changes (by nickm):
* status: new => closed
* resolution: => fixed
Old description:
> Placeholder ticket; see #20383 for "TROVE" backronym. Fix should go out
> in 0.2.9.4-alpha in the next 48 hours. Severity is "Medium".
New description:
Placeholder ticket; see #20383 for "TROVE" backronym. Fix should go out
in 0.2.9.4-alpha in the next 48 hours. Severity is "Medium".
This is fixed in 0.2.8.9 and 0.2.9.4-alpha. The changelog says:
{{{
Tor 0.2.9.4-alpha fixes a security hole in previous versions of Tor
that would allow a remote attacker to crash a Tor client, hidden
service, relay, or authority. All Tor users should upgrade to this
version, or to 0.2.8.9. Patches will be released for older versions
of Tor.
o Major features (security fixes):
- Prevent a class of security bugs caused by treating the contents
of a buffer chunk as if they were a NUL-terminated string. At
least one such bug seems to be present in all currently used
versions of Tor, and would allow an attacker to remotely crash
most Tor instances, especially those compiled with extra compiler
hardening. With this defense in place, such bugs can't crash Tor,
though we should still fix them as they occur. Closes ticket
20384 (TROVE-2016-10-001).
}}}
--
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/20384#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs