[tor-bugs] #16823 [Tor]: potential double-free in command_process_create_cell()

Tor Bug Tracker & Wiki blackhole at torproject.org
Sun Aug 16 01:22:51 UTC 2015


#16823: potential double-free in command_process_create_cell()
-------------------------+-------------------------------------------------
     Reporter:  isis     |      Owner:
         Type:  defect   |     Status:  needs_review
     Priority:  blocker  |  Milestone:
    Component:  Tor      |    Version:  Tor: 0.2.4.10-alpha
   Resolution:           |   Keywords:  tor-relay, tor-guard, security,
Actual Points:           |  024-backport, 025-backport, 026-backport
       Points:           |  Parent ID:
-------------------------+-------------------------------------------------
Changes (by isis):

 * priority:  normal => blocker
 * keywords:  tor-relay, tor-guard =>
     tor-relay, tor-guard, security, 024-backport, 025-backport,
     026-backport
 * milestone:  Tor: 0.2.7.x-final =>


Comment:

 Replying to [comment:2 yawning]:
 > We discussed this on #tor-dev, unfortunately.  Nice find.  Bumping up
 the priority, and marking for backport.
 >
 > ACK the branch, since it's as discussed.  Needs a changes file but nickm
 or I can write one if you don't feel like it.

 I added a changes file to my branch, but I tagged it `Major bugfixes
 (security, relay)` so, if it's not actually a security bug, then we should
 remove the security tag.  Or just rewrite the thing however it should be
 written, with whatever classifications are appropriate.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/16823#comment:6>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list