HomeFreeBSD

security/tor: update 0.4.8.9 → 0.4.8.10

Description

security/tor: update 0.4.8.9 → 0.4.8.10

Log: https://forum.torproject.org/t/security-release-0-4-8-10/10536

This is a security release fixing a high severity bug (TROVE-2023-007)
affecting Exit relays supporting Conflux. We strongly recommend to update as
soon as possible.

o Major bugfixes (TROVE-2023-007, exit):
  - Improper error propagation from a safety check in conflux leg
    linking lead to a desynchronization of which legs were part of a
    conflux set, ultimately causing a UAF and NULL pointer dereference
    crash on Exit relays. Fixes bug 40897; bugfix on 0.4.8.1-alpha.

o Minor features (fallbackdir):
  - Regenerate fallback directories generated on December 08, 2023.

o Minor features (geoip data):
  - Update the geoip files to match the IPFire Location Database, as
    retrieved on 2023/12/08.

o Minor bugfixes (bridges, statistics):
  - Correctly report statistics for client count over Pluggable
    transport. Fixes bug 40871; bugfix on 0.4.8.4

Reported by: George Rosamond <george@ceetonetechnology.com>

(cherry picked from commit a451cf7b9cd6a30f66696e7576e0e02cb3b4a8e8)

Details

Provenance
yuriAuthored on Dec 8 2023, 10:21 PM
Parents
R11:6dfdfcacf42d: audio/lmms: Fix plist
Branches
Unknown
Tags
Unknown