[tor-announce] Tor security advisory: OpenSSL flaw

Roger Dingledine arma at mit.edu
Thu Apr 10 08:09:20 UTC 2014


A new OpenSSL vulnerability is out this week, which can be used to reveal
memory to a connected client or server. Tor uses OpenSSL so all Tor users
(clients, relays, etc) are potentially affected.

You can read many more details about the Tor impact on our blog post:
https://blog.torproject.org/blog/openssl-bug-cve-2014-0160

We have released an updated Tor Browser Bundle:
https://blog.torproject.org/blog/tor-browser-354-released

--Roger

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 190 bytes
Desc: Digital signature
URL: <http://lists.torproject.org/pipermail/tor-announce/attachments/20140410/5c896f34/attachment.sig>


More information about the tor-announce mailing list