[Secure-testing-team] Bug#866799: tor: CVE-2017-0377: TROVE-2017-006: Path selection issue

Salvatore Bonaccorso carnil at debian.org
Sat Jul 1 19:23:55 UTC 2017


Source: tor
Version: 0.3.0.8-1
Severity: important
Tags: upstream fixed-upstream security
Forwarded: https://trac.torproject.org/projects/tor/ticket/22753

To track the bug in the Debian BTS.

Upstream Bug: https://trac.torproject.org/projects/tor/ticket/22753

https://blog.torproject.org/blog/tor-0309-released-security-update-clients
https://blog.torproject.org/blog/tor-0314-alpha-released-security-update-clients

> When choosing which guard to use for a circuit, avoid the exit's
> family along with the exit itself. Previously, the new guard selection
> logic avoided the exit, but did not consider its family.

Regards,
Salvatore



More information about the Secure-testing-team mailing list