Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package tor for openSUSE:Factory checked in at 2021-03-17 20:16:57 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/tor (Old) and /work/SRC/openSUSE:Factory/.tor.new.2401 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "tor" Wed Mar 17 20:16:57 2021 rev:90 rq:879675 version:0.4.5.7 Changes: -------- --- /work/SRC/openSUSE:Factory/tor/tor.changes 2021-02-16 22:51:20.790733421 +0100 +++ /work/SRC/openSUSE:Factory/.tor.new.2401/tor.changes 2021-03-17 20:20:10.623335737 +0100 @@ -1,0 +2,13 @@ +Tue Mar 16 23:38:53 UTC 2021 - Bernhard Wiedemann <bwiedem...@suse.com> + +- tor 0.4.5.7 + * https://lists.torproject.org/pipermail/tor-announce/2021-March/000216.html + * Fix 2 denial of service security issues + + Disable the dump_desc() function that we used to dump unparseable + information to disk (CVE-2021-28089) + + Fix a bug in appending detached signatures to a pending consensus + document that could be used to crash a directory authority + (CVE-2021-28090) + * Ship geoip files based on the IPFire Location Database + +------------------------------------------------------------------- Old: ---- tor-0.4.5.6.tar.gz tor-0.4.5.6.tar.gz.asc New: ---- tor-0.4.5.7.tar.gz tor-0.4.5.7.tar.gz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ tor.spec ++++++ --- /var/tmp/diff_new_pack.yjeOOM/_old 2021-03-17 20:20:11.267336617 +0100 +++ /var/tmp/diff_new_pack.yjeOOM/_new 2021-03-17 20:20:11.271336623 +0100 @@ -20,7 +20,7 @@ %define torgroup %{name} %define home_dir %{_localstatedir}/lib/empty Name: tor -Version: 0.4.5.6 +Version: 0.4.5.7 Release: 0 Summary: Anonymizing overlay network for TCP (The onion router) License: BSD-3-Clause ++++++ tor-0.4.5.6.tar.gz -> tor-0.4.5.7.tar.gz ++++++ /work/SRC/openSUSE:Factory/tor/tor-0.4.5.6.tar.gz /work/SRC/openSUSE:Factory/.tor.new.2401/tor-0.4.5.7.tar.gz differ: char 28, line 1