Alerts This Week
Warning Icon 1 770
Alerts This Week
Warning Icon 1 770

openSUSE Leap 15.2: 2021:1169-1 Important: tor DoS Patch

opensuse
Calendar Grey August 19, 2021
Dist Opensuse Esm H88
Vital openSUSE Security Patch: Resolution for tor Denial of Service vulnerability, significant update accessible for Leap 15.2.
An update that fixes one vulnerability is now available

Description

This update for tor fixes the following issues:

tor 0.4.6.7:

* Fix a DoS via a remotely triggerable assertion failure (boo#1189489,

TROVE-2021-007, CVE-2021-38385)

tor 0.4.6.6:

* Fix a compilation error with gcc 7, drop tor-0.4.6.5-gcc7.patch

* Enable the deterministic RNG for unit tests that covers the address set

bloomfilter-based API's

tor 0.4.6.5

* Add controller support for creating v3 onion services with client auth

* When voting on a relay with a Sybil-like appearance, add the Sybil flag

when clearing out the other flags. This lets a relay

operator know why their relay hasn't been included in the consensus

* Relays now report how overloaded they are

* Add a new DoS subsystem to control the rate of client connections for

relays

* Relays now publish statistics about v3 onions services

* Improve circuit timeout algorithm for client performance

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-1169=1

Package List

- openSUSE Leap 15.2 (x86_64):

tor-0.4.6.7-lp152.2.15.1

tor-debuginfo-0.4.6.7-lp152.2.15.1

tor-debugsource-0.4.6.7-lp152.2.15.1

References

https://www.suse.com/security/cve/CVE-2021-38385.html

https://bugzilla.suse.com/1189489

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:1169-1
Rating: important
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here