openSUSE-SU-2021:0334-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:0334-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2021:0334-1
Published
2021-02-23T17:05:00Z
Modified
2021-02-23T17:05:00Z
Summary
Security update for tor
Details

This update for tor fixes the following issues:

tor was updated to 0.4.5.6:

tor was updated to 0.4.4.7:

  • https://blog.torproject.org/node/1990

  • Stop requiring a live consensus for v3 clients and services

  • Re-entry into the network is now denied at the Exit level

  • Fix undefined behavior on our Keccak library

  • Strip '\r' characters when reading text files on Unix platforms

  • Handle partial SOCKS5 messages correctly

  • Check channels+circuits on relays more thoroughly (TROVE-2020-005, boo#1178741)

This update was imported from the openSUSE:Leap:15.2:Update update project.

References

Affected packages

SUSE:Package Hub 15 SP2 / tor

Package

Name
tor
Purl
pkg:rpm/suse/tor&distro=SUSE%20Package%20Hub%2015%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.5.6-bp152.2.6.1

Ecosystem specific

{
    "binaries":  [
        {
            "tor":  "0.4.5.6-bp152.2.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:0334-1.json"