[SECURITY] [DLA 663-1] tor security update

2016-10-18 Thread Peter Palfrader
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: tor Version: 0.2.4.27-2 It has been discovered that Tor treats the contents of some buffer chunks as if they were a NUL-terminated string. This issue could enable a remote attacker to crash a Tor client, hidden service,

[SECURITY] [DLA 982-1] tor security update

2017-06-10 Thread Peter Palfrader
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Package: tor Version: 0.2.4.29-1 CVE ID : CVE-2017-0376 Debian Bug : 864424 It has been discovered that Tor, a connection-based low-latency anonymous communication system, contains a flaw in the hidden service code. A