Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - More Tor bug updates

 
Thread Tools Search this Thread
Old 08-29-2006, 09:36 PM   #1
Default More Tor bug updates


The short version:
Upgrade to 0.1.1.23.

Impact:
A malicious entry node (the first Tor server in your path) can
route traffic through your Tor client as though you're a server. It can
only route traffic to other Tor servers though -- it can't induce any
"exit" connections.

Versions affected:
All versions of Tor in the 0.1.0.x series earlier than 0.1.0.18.
All versions of Tor in the 0.1.1.x series earlier than 0.1.1.23.
The experimental snapshot 0.1.2.1-alpha-cvs.

Solution:
Upgrade to at least Tor 0.1.1.23. If you absolutely must stay with
the 0.1.0.x series, I've put a patched tarball for the old 0.1.0.x
series at:
http://tor.eff.org/dist/tor-0.1.0.18.tar.gz
http://tor.eff.org/dist/tor-0.1.0.18.tar.gz.asc

More details:

There is a bug in older versions of Tor that allows a hostile Tor server
to crash your Tor process, or route traffic through your client to the
Tor network as though it were a server. To exploit this bug, an attacker
needs to be or compromise the first Tor server in one of your circuits.
(Other Tor servers on your path can't do it.)

This is a client-only bug; servers are not affected.

If you didn't upgrade when we released 0.1.1.23 and said "you should
upgrade"... you should upgrade.

We'll write a more detailed advisory in a little while, after more people
have upgraded.

--Roger







TwistyCreek
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Question about MS critical updates juhu A+ Certification 2 07-05-2004 01:28 PM
Re: Question about MS critical updates John Coode A+ Certification 0 06-30-2004 06:08 PM
Re: Question about MS critical updates juhu A+ Certification 0 06-30-2004 03:12 PM
Re: Question about MS critical updates Chris A+ Certification 1 06-30-2004 01:59 PM
Re: Question about MS critical updates John Loop A+ Certification 0 06-30-2004 01:09 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46