Re: [tor-bugs] #19418 [Core Tor/Tor]: i2d_RSAPublicKey retval ignored in multiple callsites

2017-08-25 Thread Tor Bug Tracker & Wiki
#19418: i2d_RSAPublicKey retval ignored in multiple callsites
-+-
 Reporter:  asn  |  Owner:  nickm
 Type:  defect   | Status:  closed
 Priority:  Medium   |  Milestone:  Tor:
 |  0.3.1.x-final
Component:  Core Tor/Tor |Version:
 Severity:  Normal   | Resolution:  fixed
 Keywords:  tor-bug-bounty, disaster-waiting-|  Actual Points:
  to-happen, review-group-22 |
Parent ID:   | Points:  0.5
 Reviewer:  asn  |Sponsor:
 |  SponsorV-can
-+-
Changes (by nickm):

 * status:  merge_ready => closed
 * resolution:   => fixed
 * milestone:  Tor: 0.3.2.x-final => Tor: 0.3.1.x-final


Comment:

 Merged  to 0.3.1; not backporting.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19418 [Core Tor/Tor]: i2d_RSAPublicKey retval ignored in multiple callsites

2017-08-25 Thread Tor Bug Tracker & Wiki
#19418: i2d_RSAPublicKey retval ignored in multiple callsites
-+-
 Reporter:  asn  |  Owner:  nickm
 Type:  defect   | Status:
 |  merge_ready
 Priority:  Medium   |  Milestone:  Tor:
 |  0.3.2.x-final
Component:  Core Tor/Tor |Version:
 Severity:  Normal   | Resolution:
 Keywords:  tor-bug-bounty, disaster-waiting-|  Actual Points:
  to-happen, review-group-22 |
Parent ID:   | Points:  0.5
 Reviewer:  asn  |Sponsor:
 |  SponsorV-can
-+-
Changes (by asn):

 * status:  needs_review => merge_ready


Comment:

 Looks good to me!

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19418 [Core Tor/Tor]: i2d_RSAPublicKey retval ignored in multiple callsites

2017-08-21 Thread Tor Bug Tracker & Wiki
#19418: i2d_RSAPublicKey retval ignored in multiple callsites
-+-
 Reporter:  asn  |  Owner:  nickm
 Type:  defect   | Status:
 |  needs_review
 Priority:  Medium   |  Milestone:  Tor:
 |  0.3.2.x-final
Component:  Core Tor/Tor |Version:
 Severity:  Normal   | Resolution:
 Keywords:  tor-bug-bounty, disaster-waiting-|  Actual Points:
  to-happen, review-group-22 |
Parent ID:   | Points:  0.5
 Reviewer:  asn  |Sponsor:
 |  SponsorV-can
-+-
Changes (by asn):

 * reviewer:   => asn


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19418 [Core Tor/Tor]: i2d_RSAPublicKey retval ignored in multiple callsites

2017-08-11 Thread Tor Bug Tracker & Wiki
#19418: i2d_RSAPublicKey retval ignored in multiple callsites
-+-
 Reporter:  asn  |  Owner:  nickm
 Type:  defect   | Status:
 |  needs_review
 Priority:  Medium   |  Milestone:  Tor:
 |  0.3.2.x-final
Component:  Core Tor/Tor |Version:
 Severity:  Normal   | Resolution:
 Keywords:  tor-bug-bounty disaster-waiting-to-  |  Actual Points:
  happen |
Parent ID:   | Points:  0.5
 Reviewer:   |Sponsor:
 |  SponsorV-can
-+-
Changes (by nickm):

 * status:  assigned => needs_review


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19418 [Core Tor/Tor]: i2d_RSAPublicKey retval ignored in multiple callsites

2017-08-11 Thread Tor Bug Tracker & Wiki
#19418: i2d_RSAPublicKey retval ignored in multiple callsites
-+-
 Reporter:  asn  |  Owner:  nickm
 Type:  defect   | Status:
 |  assigned
 Priority:  Medium   |  Milestone:  Tor:
 |  0.3.2.x-final
Component:  Core Tor/Tor |Version:
 Severity:  Normal   | Resolution:
 Keywords:  tor-bug-bounty disaster-waiting-to-  |  Actual Points:
  happen |
Parent ID:   | Points:  0.5
 Reviewer:   |Sponsor:
 |  SponsorV-can
-+-
Changes (by nickm):

 * status:  needs_review => assigned
 * owner:  (none) => nickm


Comment:

 setting owner.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19418 [Core Tor/Tor]: i2d_RSAPublicKey retval ignored in multiple callsites

2017-08-09 Thread Tor Bug Tracker & Wiki
#19418: i2d_RSAPublicKey retval ignored in multiple callsites
-+-
 Reporter:  asn  |  Owner:
 Type:  defect   | Status:
 |  needs_review
 Priority:  Medium   |  Milestone:  Tor:
 |  0.3.2.x-final
Component:  Core Tor/Tor |Version:
 Severity:  Normal   | Resolution:
 Keywords:  tor-bug-bounty disaster-waiting-to-  |  Actual Points:
  happen |
Parent ID:   | Points:  0.5
 Reviewer:   |Sponsor:
 |  SponsorV-can
-+-
Changes (by nickm):

 * status:  new => needs_review


Comment:

 So it seems our major omission here has been checking the output of
 crypto_pk_get_digest.  I have a patch for that in `bug19418_029`.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19418 [Core Tor/Tor]: i2d_RSAPublicKey retval ignored in multiple callsites

2017-06-30 Thread Tor Bug Tracker & Wiki
#19418: i2d_RSAPublicKey retval ignored in multiple callsites
-+-
 Reporter:  asn  |  Owner:
 Type:  defect   | Status:  new
 Priority:  Medium   |  Milestone:  Tor:
 |  0.3.2.x-final
Component:  Core Tor/Tor |Version:
 Severity:  Normal   | Resolution:
 Keywords:  tor-bug-bounty disaster-waiting-to-  |  Actual Points:
  happen |
Parent ID:   | Points:  0.5
 Reviewer:   |Sponsor:
-+-
Changes (by nickm):

 * keywords:  tor-bug-bounty => tor-bug-bounty disaster-waiting-to-happen
 * milestone:  Tor: unspecified => Tor: 0.3.2.x-final


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19418 [Core Tor/Tor]: i2d_RSAPublicKey retval ignored in multiple callsites

2016-06-20 Thread Tor Bug Tracker & Wiki
#19418: i2d_RSAPublicKey retval ignored in multiple callsites
+
 Reporter:  asn |  Owner:
 Type:  defect  | Status:  new
 Priority:  Medium  |  Milestone:  Tor: 0.2.9.x-final
Component:  Core Tor/Tor|Version:
 Severity:  Normal  | Resolution:
 Keywords:  tor-bug-bounty  |  Actual Points:
Parent ID:  | Points:  0.5
 Reviewer:  |Sponsor:
+
Changes (by nickm):

 * keywords:  tor-bug-bounty 029-proposed => tor-bug-bounty
 * milestone:  Tor: 0.2.??? => Tor: 0.2.9.x-final


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

Re: [tor-bugs] #19418 [Core Tor/Tor]: i2d_RSAPublicKey retval ignored in multiple callsites

2016-06-15 Thread Tor Bug Tracker & Wiki
#19418: i2d_RSAPublicKey retval ignored in multiple callsites
-+--
 Reporter:  asn  |  Owner:
 Type:  defect   | Status:  new
 Priority:  Medium   |  Milestone:  Tor: 0.2.???
Component:  Core Tor/Tor |Version:
 Severity:  Normal   | Resolution:
 Keywords:  tor-bug-bounty 029-proposed  |  Actual Points:
Parent ID:   | Points:  0.5
 Reviewer:   |Sponsor:
-+--
Changes (by asn):

 * milestone:  Tor: 0.2.9.x-final => Tor: 0.2.???


--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs

[tor-bugs] #19418 [Core Tor/Tor]: i2d_RSAPublicKey retval ignored in multiple callsites

2016-06-15 Thread Tor Bug Tracker & Wiki
#19418: i2d_RSAPublicKey retval ignored in multiple callsites
--+-
 Reporter:  asn   |  Owner:
 Type:  defect| Status:  new
 Priority:  Medium|  Milestone:  Tor: 0.2.9.x-final
Component:  Core Tor/Tor  |Version:
 Severity:  Normal|   Keywords:  tor-bug-bounty 029-proposed
Actual Points:|  Parent ID:
   Points:  0.5   |   Reviewer:
  Sponsor:|
--+-
 Hello. Here follows a bug report by `Guido Vranken` received through the
 hackerone program.

 There are various places in the codebase where we don't check the retval
 of `i2d_RSA_PublicKey()` (or its callers). That function can fail in cases
 of OOM, and this is something we should be handling correctly. This is a
 similar case to #17686.

--
Ticket URL: 
Tor Bug Tracker & Wiki 
The Tor Project: anonymity online
___
tor-bugs mailing list
tor-bugs@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs