Bug 1005213 (TROVE-2016-10-001) - VUL-0: tor: specially crafted data may crashing tor instances
Summary: VUL-0: tor: specially crafted data may crashing tor instances
Status: RESOLVED DUPLICATE of bug 1005292
Alias: TROVE-2016-10-001
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.1
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Andreas Stieger
QA Contact: Security Team bot
URL: https://trac.torproject.org/projects/...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-10-18 06:03 UTC by Andreas Stieger
Modified: 2016-10-19 12:16 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-10-18 06:03:51 UTC
From https://lists.torproject.org/pipermail/tor-announce/2016-October/000115.html

>  Tor 0.2.8.9 backports a fix for a security hole in previous versions
>  of Tor that would allow a remote attacker to crash a Tor client,
>  hidden service, relay, or authority. All Tor users should upgrade to
>  this version, or to 0.2.9.4-alpha. Patches will be released for older
>  versions of Tor.
>
>  o Major features (security fixes, also in 0.2.9.4-alpha):
>    - Prevent a class of security bugs caused by treating the contents
>      of a buffer chunk as if they were a NUL-terminated string. At
>      least one such bug seems to be present in all currently used
>      versions of Tor, and would allow an attacker to remotely crash
>      most Tor instances, especially those compiled with extra compiler
>      hardening. With this defense in place, such bugs can't crash Tor,
>      though we should still fix them as they occur. Closes ticket
>      20384 (TROVE-2016-10-001).

Remote DoS. Source patches available for 0.2.4, 0.2.5, 0.2.6, 0.2.7
https://trac.torproject.org/projects/tor/ticket/20384
Comment 1 Swamp Workflow Management 2016-10-18 22:00:22 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2016-10-19 08:44:26 UTC
dup of 1005292

*** This bug has been marked as a duplicate of bug 1005292 ***
Comment 3 Bernhard Wiedemann 2016-10-19 10:00:52 UTC
This is an autogenerated message for OBS integration:
This bug (1005213) was mentioned in
https://build.opensuse.org/request/show/436108 Factory / tor