🛡️ openSUSE-SU-2023:0361-1 — tor

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for tor

This update for tor fixes the following issues:

  • tor 0.4.8.8:
  • Mitigate an issue when Tor compiled with OpenSSL can crash during

handshake with a remote relay. (TROVE-2023-004, boo#1216873)

  • Regenerate fallback directories generated on November 03, 2023.
  • Update the geoip files to match the IPFire Location Database, as

retrieved on 2023/11/03

  • directory authority: Look at the network parameter

'maxunmeasuredbw' with the correct spelling

  • vanguards addon support: Count the conflux linked cell as

valid when it is successfully processed. This will quiet a

spurious warn in the vanguards addon

  • tor 0.4.8.7:
  • Fix an issue that prevented us from pre-building more conflux

sets after existing sets had been used

  • tor 0.4.8.6:
  • onion service: Fix a reliability issue where services were

expiring their introduction points every consensus update.

This caused connectivity issues for clients caching the old

descriptor and intro points

  • Log the input and output buffer sizes when we detect a potential

compression bomb

  • Disable multiple BUG warnings of a missing relay identity key when

starting an instance of Tor compiled without relay support

  • When reporting a pseudo-networkstatus as a bridge authority, or

answering 'ns/purpose/*' controller requests, include accurate

published-on dates from our list of router descriptors

  • Use less frightening language and lower the log-level of our

run-time ABI compatibility check message in our Zstd

compression subsystem

  • tor 0.4.8.5:
  • bugfixes creating log BUG stacktrace
  • tor 0.4.8.4:
  • Extend DoS protection to partially opened channels and known

relays

  • Dynamic Proof-Of-Work protocol to thwart flooding DoS attacks

against hidden services. Disabled by default, enable via

'HiddenServicePoW' in torrc

  • Implement conflux traffic splitting
  • Directory authorities and relays now interact properly with

directory authorities if they change addresses

  • tor 0.4.7.14:
  • bugfix affecting vanguards (onion service), and minor fixes
  • Enable support for scrypt()

Affected software

openSUSE-SU-2023:0361-1 is recorded against 1 package.

  • tor (fixed in 0.4.8.8-bp155.2.3.1)

Timeline and source

Published on 10 November 2023. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

lists.opensuse.org (Advisory)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2023-11-10
Updated 2026-08-20
Modified 2023-11-10
Fix URL N/A

Affected Packages

Software From version Fixed in
tor 0.4.8.8-bp155.2.3.1

Free Vulnerability Check

Is your site affected by openSUSE-SU-2023:0361-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2023:0361-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2023