When completing a channel, relays now check more thoroughly to make sure that it matches any pending circuits before attaching those circuits. Previously, address correctness and Ed25519 identities were not checked in this case, but only when extending circuits on an existing channel (TROVE-2020-005). . MGASA-2020-0442 - Updated tor package fixes security vulnerabilities Publication date: 03 Dec 2020 URL: https://advisories.mageia.org/MGASA-2020-0442.html Type: security Affected Mageia releases: 7 When completing a channel, relays now check more thoroughly to make sure that it matches any pending circuits before attaching those circuits. Previously, address correctness and Ed25519 identities were not checked in this case, but only when extending circuits on an existing channel (TROVE-2020-005). Channels using obsolete versions of the Tor link protocol are no longer allowed to circumvent address-canonicity checks. This is only a minor issue, since such channels have no way to set ed25519 keys, and therefore should always be rejected for circuits that specify ed25519 identities (tor#40081). The tor package has been updated to version 0.3.5.12, fixing these issues and several other bugs. See the upstream ChangeLog for details. References: - https://bugs.mageia.org/show_bug.cgi?id=27606 - https://gitlab.torproject.org/tpo/core/tor/-/blob/HEAD/ChangeLog - SRPMS: - 7/core/tor-0.3.5.12-1.mga7 . The newly released tor package addresses significant vulnerabilities within Mageia's core system, introducing improved channel authentication.. Mageia Security Advisory, Tor Package Update, Software Security, Mageia 7, Security Fix. . Severity: Important. LinuxSecurity.com Team
The package tor before version 0.3.0.9-1 is vulnerable to session hijacking. . Arch Linux Security Advisory ASA-201707-8 ======================================== Severity: Medium Date : 2017-07-11 CVE-ID : CVE-2017-0377 Package : tor Type : session hijacking Remote : Yes Link : https://security.archlinux.org/AVG-336 Summary ====== The package tor before version 0.3.0.9-1 is vulnerable to session hijacking. Resolution ========= Upgrade to 0.3.0.9-1. # pacman -Syu "tor> =0.3.0.9-1" The problem has been fixed upstream in version 0.3.0.9. Workaround ========= None. Description ========== A security issue has been found in Tor
Get the latest Linux and open source security news straight to your inbox.