[tor-bugs] #1190 [Tor - Tor client]: Renegotiation bug still present on OpenBSD 4.6 stable

Tor Bug Tracker & Wiki torproject-admin at torproject.org
Sun Aug 1 01:13:21 UTC 2010


#1190: Renegotiation bug still present on OpenBSD 4.6 stable
-------------------------------+--------------------------------------------
  Reporter:  nixmlists         |       Owner:  nickm             
      Type:  defect            |      Status:  assigned          
  Priority:  minor             |   Milestone:  Tor: 0.2.2.x-final
 Component:  Tor - Tor client  |     Version:  0.2.1.21          
Resolution:  None              |    Keywords:                    
    Parent:                    |  
-------------------------------+--------------------------------------------
Changes (by nickm):

  * status:  new => assigned
  * owner:  => nickm
  * milestone:  => Tor: 0.2.2.x-final


Old description:

> Renegotiation bug still present on OpenBSD 4.6 with
> ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/004_openssl.patch
> applied.
>
> Results in the supposedly fixed TLS renegotiation errors in .21, and
> prevents it from working. Works without the patch, but that
> leaves the whole system vulnerable.
>
>  [warn] TLS error: unexpected close while renegotiating
>
> same exact problem with 0.2.2.6-alpha
>
> OpenBSD 4.6 ships with OpenSSL 0.9.8k
>
> What is the work-around?
>
> [Automatically added by flyspray2trac: Operating System: Other]

New description:

 Renegotiation bug still present on OpenBSD 4.6 with
 ftp://ftp.openbsd.org/pub/OpenBSD/patches/4.6/common/004_openssl.patch
 applied.

 Results in the supposedly fixed TLS renegotiation errors in .21, and
 prevents it from working. Works without the patch, but that
 leaves the whole system vulnerable.

  [warn] TLS error: unexpected close while renegotiating

 same exact problem with 0.2.2.6-alpha

 OpenBSD 4.6 ships with OpenSSL 0.9.8k

 What is the work-around?

 [Automatically added by flyspray2trac: Operating System: Other]

--

-- 
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/1190#comment:3>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list