From d5c9a3d930f66ee5793a4711c112541dc37553fd Mon Sep 17 00:00:00 2001 From: John Helmert III Date: Fri, 9 Jul 2021 21:54:14 -0500 Subject: [ GLSA 202107-25 ] Tor: Multiple vulnerabilities Signed-off-by: John Helmert III --- glsa-202107-25.xml | 69 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 69 insertions(+) create mode 100644 glsa-202107-25.xml (limited to 'glsa-202107-25.xml') diff --git a/glsa-202107-25.xml b/glsa-202107-25.xml new file mode 100644 index 00000000..5e9b2a4f --- /dev/null +++ b/glsa-202107-25.xml @@ -0,0 +1,69 @@ + + + + Tor: Multiple vulnerabilities + Multiple vulnerabilities have been found in Tor, the worst of which + could result in a Denial of Service condition. + + tor + 2021-07-10 + 2021-07-10 + 776586 + 795969 + remote + + + 0.4.6.5 + 0.4.5.9 + 0.4.4.9 + 0.4.6.5 + + + +

Tor is an implementation of second generation Onion Routing, a + connection-oriented anonymizing communication service. +

+
+ +

Multiple vulnerabilities have been discovered in Tor. Please review the + CVE identifiers referenced below for details. +

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Tor 0.4.6.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-vpn/tor-0.4.6.5" + + +

All Tor 0.4.5.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-vpn/tor-0.4.5.9" + + +

All Tor 0.4.4.x users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-vpn/tor-0.4.4.9" + +
+ + CVE-2021-28089 + CVE-2021-28090 + CVE-2021-34548 + CVE-2021-34549 + CVE-2021-34550 + + sam_c + sam_c +
-- cgit v1.2.3-65-gdbad