MGASA-2017-0353
Dashboard / Vulnerabilities / MGASA-2017-0353
Summary: Updated tor packages fix security vulnerability
Details: Due to the code that reports an error during the construction of an introduction point circuit, it is possible that some hidden services will sometimes write sensitive information into their logs if the SafeLogging option is disabled. Note that SafeLogging is enabled by default (CVE-2017-0380).
References: https://advisories.mageia.org/MGASA-2017-0353.html, https://bugs.mageia.org/show_bug.cgi?id=21740, https://lists.torproject.org/pipermail/tor-talk/2017-September/043585.html, https://blog.torproject.org/new-tor-stable-releases-02815-02912-03011-fix-onion-service-security-issue
Affected packages
Package
Name: tor
Purl: pkg:rpm/mageia/tor?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
