pkgsrc-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

pkg/43103: Maintainer update: net/tor to 0.2.1.25 (security fix)



>Number:         43103
>Category:       pkg
>Synopsis:       Maintainer update: net/tor to 0.2.1.25 (security fix)
>Confidential:   no
>Severity:       serious
>Priority:       medium
>Responsible:    pkg-manager
>State:          open
>Class:          change-request
>Submitter-Id:   net
>Arrival-Date:   Fri Apr 02 09:40:00 +0000 2010
>Originator:     Christian Sturm
>Release:        
>Organization:
>Environment:
>Description:
This patch updates net/tor from 0.2.1.24 to 2.1.25
After commit a pull-up should also be considered, because
it's only only containing bug fixes, but fixes potential
security bugs.

Changes in version 0.2.1.25 - 2010-03-16
  o Major bugfixes:
    - Fix a regression from our patch for bug 1244 that caused relays
      to guess their IP address incorrectly if they didn't set Address
      in their torrc and/or their address fails to resolve. Bugfix on
      0.2.1.23; fixes bug 1269.
    - When freeing a session key, zero it out completely. We only zeroed
      the first ptrsize bytes. Bugfix on 0.0.2pre8. Discovered and
      patched by ekir. Fixes bug 1254.

  o Minor bugfixes:
    - Fix a dereference-then-NULL-check sequence when publishing
      descriptors. Bugfix on 0.2.1.5-alpha. Discovered by ekir; fixes
      bug 1255.
    - Fix another dereference-then-NULL-check sequence. Bugfix on
      0.2.1.14-rc. Discovered by ekir; fixes bug 1256.
    - Make sure we treat potentially not NUL-terminated strings correctly.
      Bugfix on 0.1.1.13-alpha. Discovered by rieo; fixes bug 1257.

>How-To-Repeat:

>Fix:
begin 644 tor-0.2.1.25.patch.gz
M'XL(""6UM4L``W1O<BTP+C(N,2XR-2YP871C:`"]D5U+PS`4AJ_77Y%+A;4]
M24^^Q`FB@KN8%YM_(!\GHRBMM&7H?KTM*AOJK@0#)PD<\ISW(<LFTNL%6[DG
M2O4S98N_KVQ]LV$3[(*58==W;3N4+T_;O@ME0T,YM%WY-6Z^RSH:NIIV=;-E
MW7CT==LP7FB>Q3HEEG?3_1`/`V:7[':Y>7RX7MTM9K.1ED,A"EX(S/(\SZY.
M=&6V_%"-=3_436K_2?5KW$E5A(,JPB%>-9=AK%%W<W_-V=FQ:3&XKMCNS]F"
M:2]YL"22=5%Z#9&<2)YTI84)4:'@50H2)LYZ=<L5G"1%%91$:Y,/%H5+XTX2
MC#,D9066.W+1<VFG1/6>3G)$9951R/S;0/WGG_Q0D$</.`]<JTJC)]1&2(]>
M)P?@Y9A':!W!5`:$&#F_*!R32%GN+2!!1-2^2M)"XF1)<X_1N0@"?#1Q2O1=
2X9@C$)0U\E/A'::<%:<D`P``
`
end



Home | Main Index | Thread Index | Old Index