🛡️ openSUSE-SU-2023:0361-1 — tor
Description
Security update for tor
This update for tor fixes the following issues:
- tor 0.4.8.8:
- Mitigate an issue when Tor compiled with OpenSSL can crash during
handshake with a remote relay. (TROVE-2023-004, boo#1216873)
- Regenerate fallback directories generated on November 03, 2023.
- Update the geoip files to match the IPFire Location Database, as
retrieved on 2023/11/03
- directory authority: Look at the network parameter
'maxunmeasuredbw' with the correct spelling
- vanguards addon support: Count the conflux linked cell as
valid when it is successfully processed. This will quiet a
spurious warn in the vanguards addon
- tor 0.4.8.7:
- Fix an issue that prevented us from pre-building more conflux
sets after existing sets had been used
- tor 0.4.8.6:
- onion service: Fix a reliability issue where services were
expiring their introduction points every consensus update.
This caused connectivity issues for clients caching the old
descriptor and intro points
- Log the input and output buffer sizes when we detect a potential
compression bomb
- Disable multiple BUG warnings of a missing relay identity key when
starting an instance of Tor compiled without relay support
- When reporting a pseudo-networkstatus as a bridge authority, or
answering 'ns/purpose/*' controller requests, include accurate
published-on dates from our list of router descriptors
- Use less frightening language and lower the log-level of our
run-time ABI compatibility check message in our Zstd
compression subsystem
- tor 0.4.8.5:
- bugfixes creating log BUG stacktrace
- tor 0.4.8.4:
- Extend DoS protection to partially opened channels and known
relays
- Dynamic Proof-Of-Work protocol to thwart flooding DoS attacks
against hidden services. Disabled by default, enable via
'HiddenServicePoW' in torrc
- Implement conflux traffic splitting
- Directory authorities and relays now interact properly with
directory authorities if they change addresses
- tor 0.4.7.14:
- bugfix affecting vanguards (onion service), and minor fixes
- Enable support for scrypt()
Affected software
openSUSE-SU-2023:0361-1 is recorded against 1 package.
- tor (fixed in 0.4.8.8-bp155.2.3.1)
Timeline and source
Published on 10 November 2023. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| tor | — | 0.4.8.8-bp155.2.3.1 |
References
Similar Threats
- Low CVE-2026-44597
- Low CVE-2026-44599
- Low CVE-2026-44600
- Low CVE-2026-44601
- Unknown DEBIAN-CVE-2026-44597
Free Vulnerability Check
Is your site affected by openSUSE-SU-2023:0361-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2023:0361-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.