Overview

Request 900013 accepted

- tor 0.4.5.9
* Don't allow relays to spoof RELAY_END or RELAY_RESOLVED cell (CVE-2021-34548, boo#1187322)
* Detect more failure conditions from the OpenSSL RNG code (boo#1187323)
* Resist a hashtable-based CPU denial-of-service attack against relays (CVE-2021-34549, boo#1187324)
* Fix an out-of-bounds memory access in v3 onion service descriptor parsing (CVE-2021-34550, boo#1187325)

- tor 0.4.5.8
* https://lists.torproject.org/pipermail/tor-announce/2021-May/000219.html
* allow Linux sandbox with Glibc 2.33
* work with autoconf 2.70+
* several other minor features and bugfixes (see announcement)

- fix packaging warnings related to tor-master service

- Fix logging issue due to systemd picking up stdout - boo#1181244
Continue to log notices to syslog by default.
- actually build with lzma/zstd
- skip i586 tests (boo#1179331)

Loading...

Leap Reviewbot's avatar

network/tor@b4de1f96519aecfd25530ee3d881b285 -> openSUSE:Backports:SLE-15-SP3:Update/tor

expected origin is 'None' (unchanged)

Request History
Bernhard Wiedemann's avatar

bmwiedemann created request

- tor 0.4.5.9
* Don't allow relays to spoof RELAY_END or RELAY_RESOLVED cell (CVE-2021-34548, boo#1187322)
* Detect more failure conditions from the OpenSSL RNG code (boo#1187323)
* Resist a hashtable-based CPU denial-of-service attack against relays (CVE-2021-34549, boo#1187324)
* Fix an out-of-bounds memory access in v3 onion service descriptor parsing (CVE-2021-34550, boo#1187325)

- tor 0.4.5.8
* https://lists.torproject.org/pipermail/tor-announce/2021-May/000219.html
* allow Linux sandbox with Glibc 2.33
* work with autoconf 2.70+
* several other minor features and bugfixes (see announcement)

- fix packaging warnings related to tor-master service

- Fix logging issue due to systemd picking up stdout - boo#1181244
Continue to log notices to syslog by default.
- actually build with lzma/zstd
- skip i586 tests (boo#1179331)


Factory Auto's avatar

factory-auto accepted review

Check script succeeded


Saul Goodman's avatar

licensedigger accepted review

ok


Maintenance Bot's avatar

maintbot added factory-source as a reviewer


Maintenance Bot's avatar

maintbot accepted review

ok


Source in Factory Checker's avatar

factory-source accepted review

ok


Source in Factory Checker's avatar

factory-source approved review

ok


Marcus Meissner's avatar

msmeissn moved maintenance target to openSUSE:Maintenance:16514


Marcus Meissner's avatar

msmeissn accepted request

accepted request 900013:Thanks!

For information about the update, see https://build.opensuse.org/project/maintenance_incidents/openSUSE:Maintenance

openSUSE Build Service is sponsored by