Update Info

openSUSE-2017-1336


Security update for tor


Type: security
Severity: moderate
Issued: 2017-12-02
Description:
This update for tor fixes vulnerabilities that allowed some
traffic confirmation, DoS and other attacks (bsc#1070849):

- CVE-2017-8819: Replay-cache ineffective for v2 onion services
- CVE-2017-8820: Remote DoS attack against directory authorities
- CVE-2017-8821: An attacker can make Tor ask for a password
- CVE-2017-8822: Relays can pick themselves in a circuit path
- CVE-2017-8823: Use-after-free in onion service v2

              

Packages


  • tor-0.3.1.9-8.1