lp:ubuntu/dapper-security/tor
- Get this branch:
- bzr branch lp:ubuntu/dapper-security/tor
Branch merges
Branch information
- Owner:
- Ubuntu branches
- Status:
- Mature
Recent revisions
- 8. By William Alexander Grant <email address hidden>
-
* SECURITY UPDATE: Fix clients being exploited as servers.
* src/or/connection_ edge.c, src/or/ circuitbuild. c, src/or/command.c:
If a routing request is recieved, ensure that tor is in fact configured as
as server. If it is not, drop the request. Previously, a malicious entry
node could route traffic through a client as though it was a server.
* References:
- CVE-2006-4508
- http://archives. seul.org/ or/announce/ Aug-2006/ msg00001. html - 7. By Michael F. Rimbert <email address hidden>
-
Added check for /var/run/tor in case /var/run is on a tmpfs.
- 5. By Barry deFreese
-
Add lsb init functions (Closes Malone #2820)
Thanks to David Mandelberg for the patch - 4. By Peter Palfrader
-
* New upstream version - changes, among others:
- Fixes the other half of the bug with crypto handshakes.
* Since gs-gpl on s390 is broken (#321435) and unable to
build PDFs of our images for the design paper this version
ships them in the source and uses them on s390, should building
them from source really fail.
* Increase standards-version from 3.6.1 to 3.6.2. No changes
necessary. - 3. By Peter Palfrader
-
* New upstream version.
* Update debian/copyright (it's 2005).
* Add sharedscripts tor logrotate.d/tor.
Branch metadata
- Branch format:
- Branch format 7
- Repository format:
- Bazaar repository format 2a (needs bzr 1.16 or later)