Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-29-2006, 09:36 PM
TwistyCreek
Guest
 
Posts: n/a
Default More Tor bug updates

The short version:
Upgrade to 0.1.1.23.

Impact:
A malicious entry node (the first Tor server in your path) can
route traffic through your Tor client as though you're a server. It can
only route traffic to other Tor servers though -- it can't induce any
"exit" connections.

Versions affected:
All versions of Tor in the 0.1.0.x series earlier than 0.1.0.18.
All versions of Tor in the 0.1.1.x series earlier than 0.1.1.23.
The experimental snapshot 0.1.2.1-alpha-cvs.

Solution:
Upgrade to at least Tor 0.1.1.23. If you absolutely must stay with
the 0.1.0.x series, I've put a patched tarball for the old 0.1.0.x
series at:
http://tor.eff.org/dist/tor-0.1.0.18.tar.gz
http://tor.eff.org/dist/tor-0.1.0.18.tar.gz.asc

More details:

There is a bug in older versions of Tor that allows a hostile Tor server
to crash your Tor process, or route traffic through your client to the
Tor network as though it were a server. To exploit this bug, an attacker
needs to be or compromise the first Tor server in one of your circuits.
(Other Tor servers on your path can't do it.)

This is a client-only bug; servers are not affected.

If you didn't upgrade when we released 0.1.1.23 and said "you should
upgrade"... you should upgrade.

We'll write a more detailed advisory in a little while, after more people
have upgraded.

--Roger






Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
New updates to free popular Java (J2ME) apps (Google Maps & Mail, Opera Mini) John Navas alt.cellular.cingular 20 03-05-2007 04:08 PM
New updates to free popular Java (J2ME) apps (Google Maps & Mail, Opera Mini) John Navas alt.internet.wireless 13 03-05-2007 03:17 PM
Computer Spares Price list updates @ http://www.pcprice.info |INDIA| k.s.basker@gmail.com alt.comp.hardware 0 11-25-2006 08:24 AM
More Microsoft updates! Zak alt.computer.security 20 08-12-2006 11:46 PM
Problems accessing a site since Norton Anti Virus Updates Johanna Damen alt.internet.wireless 2 10-15-2005 09:24 PM


All times are GMT. The time now is 10:57 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45