openSUSE-SU-2022:10209-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10209-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2022:10209-1
Published
2022-11-20T19:01:41Z
Modified
2022-11-20T19:01:41Z
Summary
Security update for tor
Details

This update for tor fixes the following issues:

tor 0.4.7.11:

  • Improve security of DNS cache by randomly clipping the TTL value (boo#1205307, TROVE-2021-009)
  • Improved defenses against network-wide DoS, multiple counters and metrics added to MetricsPorts
  • Apply circuit creation anti-DoS defenses if the outbound circuit max cell queue size is reached too many times. This introduces two new consensus parameters to control the queue size limit and number of times allowed to go over that limit.
  • Directory authority updates
  • IPFire database and geoip updates
  • Bump the maximum amount of CPU that can be used from 16 to 128. The NumCPUs torrc option overrides this hardcoded maximum.
  • onion service: set a higher circuit build timeout for opened client rendezvous circuit to avoid timeouts and retry load
  • Make the service retry a rendezvous if the circuit is being repurposed for measurements
References

Affected packages

SUSE:Package Hub 15 SP3 / tor

Package

Name
tor
Purl
pkg:rpm/suse/tor&distro=SUSE%20Package%20Hub%2015%20SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.7.11-bp154.2.9.1

Ecosystem specific

{
    "binaries":  [
        {
            "tor":  "0.4.7.11-bp154.2.9.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10209-1.json"

SUSE:Package Hub 15 SP4 / tor

Package

Name
tor
Purl
pkg:rpm/suse/tor&distro=SUSE%20Package%20Hub%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.7.11-bp154.2.9.1

Ecosystem specific

{
    "binaries":  [
        {
            "tor":  "0.4.7.11-bp154.2.9.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10209-1.json"

openSUSE:Leap 15.3 / tor

Package

Name
tor
Purl
pkg:rpm/opensuse/tor&distro=openSUSE%20Leap%2015.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.7.11-bp154.2.9.1

Ecosystem specific

{
    "binaries":  [
        {
            "tor":  "0.4.7.11-bp154.2.9.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10209-1.json"

openSUSE:Leap 15.4 / tor

Package

Name
tor
Purl
pkg:rpm/opensuse/tor&distro=openSUSE%20Leap%2015.4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.7.11-bp154.2.9.1

Ecosystem specific

{
    "binaries":  [
        {
            "tor":  "0.4.7.11-bp154.2.9.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10209-1.json"