Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

openSUSE Backports Moderate: 2023:0361-1 Tor DoS Enhancements

opensuse
Calendar Grey November 10, 2023
Dist Opensuse Esm H88
This maintenance release tackles several vulnerabilities in the system, improving overall performance and reducing the risk of exploitation.
An update that contains security fixes can now be installed

Description

This update for tor fixes the following issues:

- tor 0.4.8.8:

* Mitigate an issue when Tor compiled with OpenSSL can crash during

handshake with a remote relay. (TROVE-2023-004, boo#1216873)

* Regenerate fallback directories generated on November 03, 2023.

* Update the geoip files to match the IPFire Location Database, as

retrieved on 2023/11/03

* directory authority: Look at the network parameter "maxunmeasuredbw"

with the correct spelling

* vanguards addon support: Count the conflux linked cell as valid when

it is successfully processed. This will quiet a spurious warn in the

vanguards addon

- tor 0.4.8.7:

* Fix an issue that prevented us from pre-building more conflux sets

after existing sets had been used

- tor 0.4.8.6:

* onion service: Fix a reliability issue where services were expiring

their introduction points every consensus update. This caused

connectivity issues...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2023-361=1

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2023-361=1

Package List

- openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64):

tor-0.4.8.8-bp155.2.3.1

tor-debuginfo-0.4.8.8-bp155.2.3.1

tor-debugsource-0.4.8.8-bp155.2.3.1

- openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64):

tor-0.4.8.8-bp154.2.15.1

References

https://bugzilla.suse.com/1216873

Announcement ID: openSUSE-SU-2023:0361-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP4 openSUSE Backports SLE-15-SP5 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here