PT-2021-27330 · Tor · Tor

Published

2021-02-23

·

Updated

2021-02-23

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: tor versions prior to 0.4.4.7 tor versions prior to 0.4.5.6
Description: The issue concerns updates to the tor software, which include various fixes and improvements. These updates introduce a new MetricsPort HTTP interface, support IPv6 in the torrc Address option, and add event-tracing library support for USDT and LTTng-UST. Additionally, they address issues such as undefined behavior on the Keccak library, handle partial SOCKS5 messages correctly, and check channels and circuits on relays more thoroughly.
Recommendations: For tor versions prior to 0.4.4.7, update to version 0.4.4.7 or later. For tor versions prior to 0.4.5.6, update to version 0.4.5.6 or later.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

OPENSUSE-SU-2021:0334-1

Affected Products

Tor