forwarded 648253 https://trac.torproject.org/projects/tor/ticket/4453
tags 648253 confirmed
thanks

On Wed, Nov 09, 2011 at 06:55:01PM -0500, Michael Gold wrote:
> I run Tor on a low SocksPort to prevent non-root accounts from
> impersonating the server.  The latest version of Torbutton silently
> resets the port to 9050 on every startup.  This normally prevents it
> from working, but also introduces a security hole because any
> unprivileged user could bind to that port and observe web traffic.
> 
> A workaround is to set the TOR_SOCKS_PORT environment variable to the
> proper number.

This issue has been introduced in 1.4.4 (commit 95edaab9644). It looks
simple enough, expect a fix soon.

Cheers,
-- 
Jérémy Bobbio                        .''`. 
[email protected]                    : :Ⓐ  :  # apt-get install anarchism
                                    `. `'` 
                                      `-   

Attachment: signature.asc
Description: Digital signature

Reply via email to