Hello!
There are new releases available at https://dist.torproject.org/ ; please remember to check the signatures.
These releases fix TROVE-2019-001, a possible security bug involving the KIST cell scheduler code in versions 0.3.2.1-alpha and later. We are not certain that it is possible to exploit this bug in the wild, but out of an abundence caution, we recommend that all affected users upgrate. The potential impact is a remote denial-of-service attack against clients or relays.
Please remember that 0.3.3.12 is is our last anticipated release in the 0.3.3.x series; support for that series will end next week. Other current supported stable release series are:
0.2.9.x (long term support, end of life at Jan 1, 2020) 0.3.4.x (end-of-life at June 10, 2019) 0.3.5.x (long-term support, end of life at Feb 1, 2022) 0.4.0.x (currently in alpha; planned to be stable in April 2019 and supported until at least Jan 2020)
You can find all of the changelogs at: https://gitweb.torproject.org/tor.git/tree/ChangeLog?h=tor-0.3.3.12 https://gitweb.torproject.org/tor.git/tree/ChangeLog?h=tor-0.3.4.11 https://gitweb.torproject.org/tor.git/tree/ChangeLog?h=tor-0.3.5.8 https://gitweb.torproject.org/tor.git/tree/ChangeLog?h=tor-0.4.0.2-alpha
I'll be sending out an official announcement soon.
yrs,
tor-packagers@lists.torproject.org