Re: [tor-bugs] #31533 [Applications/GetTor]: Require Twisted 19.7.0 because it fixes CVE-2019-12855 in jabber

2020-04-06 Thread Tor Bug Tracker & Wiki
#31533: Require Twisted 19.7.0 because it fixes CVE-2019-12855 in jabber
-+---
 Reporter:  teor |  Owner:  (none)
 Type:  defect   | Status:  closed
 Priority:  Medium   |  Milestone:
Component:  Applications/GetTor  |Version:
 Severity:  Normal   | Resolution:  not a bug
 Keywords:   |  Actual Points:
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+---
Changes (by teor):

 * status:  needs_information => closed
 * resolution:   => not a bug


Comment:

 This bug is about gettor's  requirements.txt, not the Debian package.

 It looks like you don't need to worry about this bug, but I'm just about
 to file another one.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #31533 [Applications/GetTor]: Require Twisted 19.7.0 because it fixes CVE-2019-12855 in jabber

2020-03-04 Thread Tor Bug Tracker & Wiki
#31533: Require Twisted 19.7.0 because it fixes CVE-2019-12855 in jabber
-+---
 Reporter:  teor |  Owner:  (none)
 Type:  defect   | Status:  needs_information
 Priority:  Medium   |  Milestone:
Component:  Applications/GetTor  |Version:
 Severity:  Normal   | Resolution:
 Keywords:   |  Actual Points:
Parent ID:   | Points:
 Reviewer:   |Sponsor:
-+---
Changes (by cohosh):

 * status:  new => needs_information


Comment:

 We don't support XMPP anymore for gettor, but this is a good reminder to
 make sure we're up to date on our requirements.

 We use the official `python3-twisted` debian repository. I just checked
 and the current version is `17.9.0-2`. Do we need to worry about this?

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

[tor-bugs] #31533 [Applications/GetTor]: Require Twisted 19.7.0 because it fixes CVE-2019-12855 in jabber

2019-08-26 Thread Tor Bug Tracker & Wiki
#31533: Require Twisted 19.7.0 because it fixes CVE-2019-12855 in jabber
-+
 Reporter:  teor |  Owner:  (none)
 Type:  defect   | Status:  new
 Priority:  Medium   |  Milestone:
Component:  Applications/GetTor  |Version:
 Severity:  Normal   |   Keywords:
Actual Points:   |  Parent ID:
   Points:   |   Reviewer:
  Sponsor:   |
-+
 Does gettor use the jabber protocol?

 If it does, we need to require Twisted 19.7.0 in gettor:
 http://cve.circl.lu/cve/CVE-2019-12855

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs