It has been discovered that Tor, a connection-based low-latency anonymous communication system, contains a flaw in the hidden service code. A remote attacker can take advantage of this flaw to cause a hidden service to crash with an assertion failure (TROVE-2017-005). . Hash: SHA256 Package : tor Version : 0.2.4.29-1 CVE ID : CVE-2017-0376 Debian Bug : 864424 It has been discovered that Tor, a connection-based low-latency anonymous communication system, contains a flaw in the hidden service code. A remote attacker can take advantage of this flaw to cause a hidden service to crash with an assertion failure (TROVE-2017-005). For Debian 7 "Wheezy", this problem has been fixed in version 0.2.4.29-1. We recommend that you upgrade your tor packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The vulnerability in Tor's concealed service feature may allow distant hackers to compromise systems. Update your Tor software to safeguard your network.. Tor Flaw, Debian Update, Security Patch. . LinuxSecurity.com Team
Several vulnerabilities have been discovered in Tor, a connection-based low-latency anonymous communication system: CVE-2015-2928 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3216-1
Get the latest Linux and open source security news straight to your inbox.