Bug 16729 - Update request: tor (fix logging privacy issue)
Summary: Update request: tor (fix logging privacy issue)
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL: http://lwn.net/Vulnerabilities/656901/
Whiteboard: MGA4TOO has_procedure advisory MGA5-6...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2015-09-09 20:04 CEST by Jani Välimaa
Modified: 2015-09-15 16:56 CEST (History)
3 users (show)

See Also:
Source RPM: tor
CVE:
Status comment:


Attachments

Description Jani Välimaa 2015-09-09 20:04:08 CEST
Tor was updated to fix one logging privacy issue.

Reproducible: 

Steps to Reproduce:
Jani Välimaa 2015-09-09 20:05:04 CEST

CC: (none) => jani.valimaa
See Also: (none) => https://bugzilla.suse.com/show_bug.cgi?id=943362

Comment 1 Jani Välimaa 2015-09-09 20:07:30 CEST
Proposed advisory
#################
Tor was updated to fix one logging privacy issue.

The following issue was fixed:

* Malformed hostnames in socks5 requests were written to the log regardless of SafeLogging option

References:
https://bugzilla.suse.com/show_bug.cgi?id=943362
https://trac.torproject.org/projects/tor/ticket/16891
https://bugs.mageia.org/show_bug.cgi?id=16729
Comment 2 Jani Välimaa 2015-09-09 20:09:57 CEST
Mageia 5 RPM/SRPM:
tor-0.2.5.12-1.1.mga5

Mageia 4 RPM/SRPM:
tor-0.2.4.27-1.1.mga4

Whiteboard: (none) => MGA4TOO

Jani Välimaa 2015-09-09 20:12:25 CEST

See Also: (none) => https://trac.torproject.org/projects/tor/ticket/16891

David Walser 2015-09-12 01:08:10 CEST

URL: (none) => http://lwn.net/Vulnerabilities/656901/

Comment 3 Vladimir Zawalinski 2015-09-15 06:48:30 CEST
Started tor as previously installed and did a search using packaged tor browser.
Changed repo to update-testing. installed 2.5.12. This did not update the browser from 4.5.2, only the connection client.
Restarted the tor-browser, repeated the search. No obvious issues.

CC: (none) => vzawalin1
Whiteboard: MGA4TOO => MGA4TOO MGA5-64-OK

Comment 4 claire robinson 2015-09-15 14:41:32 CEST
Testing complete mga4 32

Started tor service and configured firefox to use socks proxy of localhost with port 9050. Check it was connecting through tor at https://check.torproject.org

Whiteboard: MGA4TOO MGA5-64-OK => MGA4TOO MGA5-64-OK mga4-32-ok

Comment 5 claire robinson 2015-09-15 15:38:30 CEST
Validating. Advisory uploaded from comment 1 & comment 2.

Please push to 4 & 5 updates

Thanks

Keywords: (none) => validated_update
Whiteboard: MGA4TOO MGA5-64-OK mga4-32-ok => MGA4TOO has_procedure advisory MGA5-64-OK mga4-32-ok
CC: (none) => sysadmin-bugs

Comment 6 Mageia Robot 2015-09-15 16:56:05 CEST
An update for this issue has been pushed to Mageia Updates repository.

http://advisories.mageia.org/MGAA-2015-0124.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.