-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Fri, 22 Feb 2019 09:29:07 +0100
Source: tor
Binary: tor tor-geoipdb
Architecture: source
Version: 0.4.0.2-alpha-1
Distribution: experimental
Urgency: medium
Maintainer: Peter Palfrader <wea...@debian.org>
Changed-By: Peter Palfrader <wea...@debian.org>
Description:
 tor        - anonymizing overlay network for TCP
 tor-geoipdb - GeoIP database for Tor
Changes:
 tor (0.4.0.2-alpha-1) experimental; urgency=medium
 .
   * New upstream version.
     - Includes a fix for a medium-severity security bug:
       Make KIST consider the outbuf length when computing what it can
       put in the outbuf. Previously, KIST acted as though the outbuf
       were empty, which could lead to the outbuf becoming too full. It
       is possible that an attacker could exploit this bug to cause a Tor
       client or relay to run out of memory and crash. Fixes bug 29168;
       bugfix on 0.3.2.1-alpha. This issue is also being tracked as
       TROVE-2019-001 and CVE-2019-8955.
Checksums-Sha1:
 1d9c47043eb406db87575d08fb3364dc2c689cd5 2003 tor_0.4.0.2-alpha-1.dsc
 3a80fce946e2b2da1dcfb0718f266218c1190313 7156129 tor_0.4.0.2-alpha.orig.tar.gz
 a93f5b31d879a8e46095199ad1b0126743a1549c 51236 tor_0.4.0.2-alpha-1.diff.gz
Checksums-Sha256:
 e9751167ae9d3743359b96763b27aa7169c96b0fbaa58124b1db7e942da14c2d 2003 
tor_0.4.0.2-alpha-1.dsc
 6d2c6fbf975be2cb7c677102fa5f29c4ad23457ec1871f6ba50f8060fecd60b6 7156129 
tor_0.4.0.2-alpha.orig.tar.gz
 d3bfed0b4a1f660b1a8f9221554fc4c4a2da9dbc4b13bf36be8ba9e8d07aa88b 51236 
tor_0.4.0.2-alpha-1.diff.gz
Files:
 3afcd4176d9b27845f929be0c6179f4b 2003 net optional tor_0.4.0.2-alpha-1.dsc
 192acd56206f76f8ac2c8c48bd9b1d20 7156129 net optional 
tor_0.4.0.2-alpha.orig.tar.gz
 f59601c3b85993e090d4a247a55b6a41 51236 net optional tor_0.4.0.2-alpha-1.diff.gz

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEs4PXhajJL968BgN2hgLIIDhyMx8FAlxy/ycACgkQhgLIIDhy
Mx/21gf+OqTCyFlo5L1jrE5rmG43iJhHAgwrE13diAQZcnXPqGoStimmz8nG8s7T
wy0GJn6qpqjoRZ5VtUzI4OAaGKTIbUxr+B9pizvwWWHBYkjw2sF3nMR5cFJtPd96
/A/fXv2Rf5DK0RHqZw0XhuxYMc6eZJG53pF5o6WyJWfRnGSB//kRlgDgOqFlHwZJ
NquA4HIcRR4yU8uFTtc6wKpBT65WsOHkBSvcmUP1unJSSxVIrdklgT5vhjbiMu8W
aslOwh8W/fqBNBgYkK3m0ME6gMA3o3rG315IEPWUa9d2yq8zGojylB1dcSy4JyMq
rHNUHeRIkafYxOKeZLpdc72bGpqkcw==
=Zcwx
-----END PGP SIGNATURE-----

Reply via email to