| Summary: | Update request: tor (fix logging privacy issue) | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Jani Välimaa <jani.valimaa> |
| Component: | RPM Packages | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Normal | CC: | jani.valimaa, sysadmin-bugs, vzawalin1 |
| Version: | 5 | Keywords: | validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://lwn.net/Vulnerabilities/656901/ | ||
| See Also: |
https://bugzilla.suse.com/show_bug.cgi?id=943362 https://trac.torproject.org/projects/tor/ticket/16891 |
||
| Whiteboard: | MGA4TOO has_procedure advisory MGA5-64-OK mga4-32-ok | ||
| Source RPM: | tor | CVE: | |
| Status comment: | |||
|
Description
Jani Välimaa
2015-09-09 20:04:08 CEST
Jani Välimaa
2015-09-09 20:05:04 CEST
CC:
(none) =>
jani.valimaa Proposed advisory ################# Tor was updated to fix one logging privacy issue. The following issue was fixed: * Malformed hostnames in socks5 requests were written to the log regardless of SafeLogging option References: https://bugzilla.suse.com/show_bug.cgi?id=943362 https://trac.torproject.org/projects/tor/ticket/16891 https://bugs.mageia.org/show_bug.cgi?id=16729 Mageia 5 RPM/SRPM: tor-0.2.5.12-1.1.mga5 Mageia 4 RPM/SRPM: tor-0.2.4.27-1.1.mga4 Whiteboard:
(none) =>
MGA4TOO
Jani Välimaa
2015-09-09 20:12:25 CEST
See Also:
(none) =>
https://trac.torproject.org/projects/tor/ticket/16891
David Walser
2015-09-12 01:08:10 CEST
URL:
(none) =>
http://lwn.net/Vulnerabilities/656901/ Started tor as previously installed and did a search using packaged tor browser. Changed repo to update-testing. installed 2.5.12. This did not update the browser from 4.5.2, only the connection client. Restarted the tor-browser, repeated the search. No obvious issues. CC:
(none) =>
vzawalin1 Testing complete mga4 32 Started tor service and configured firefox to use socks proxy of localhost with port 9050. Check it was connecting through tor at https://check.torproject.org Whiteboard:
MGA4TOO MGA5-64-OK =>
MGA4TOO MGA5-64-OK mga4-32-ok Validating. Advisory uploaded from comment 1 & comment 2. Please push to 4 & 5 updates Thanks Keywords:
(none) =>
validated_update An update for this issue has been pushed to Mageia Updates repository. http://advisories.mageia.org/MGAA-2015-0124.html Status:
NEW =>
RESOLVED |