[tor-bugs] #17027 [Tor]: policies_parse_exit_policy_internal should block all IPv4 and IPv6 local addresses

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Nov 16 02:33:33 UTC 2015


#17027: policies_parse_exit_policy_internal should block all IPv4 and IPv6 local
addresses
-------------------------------------------------+-------------------------
 Reporter:  teor                                 |          Owner:
     Type:  defect                               |         Status:
 Priority:  High                                 |  needs_revision
Component:  Tor                                  |      Milestone:  Tor:
 Severity:  Normal                               |  0.2.6.x-final
 Keywords:  TorCoreTeam201512, security,         |        Version:  Tor:
  026-backport, 027-backport                     |  unspecified
Parent ID:                                       |     Resolution:
  Sponsor:                                       |  Actual Points:
                                                 |         Points:
-------------------------------------------------+-------------------------

Comment (by teor):

 I'm working on this branch rebased on 0.2.7.4-rc in bug17027-reject-
 private-027.

 Forward-porting to 0.2.8 should simply require a merge.

 To backport this to 0.2.6:
 * we'll also need (some of) the documentation from ipv6-exitpolicy-docs;
 * we might want to exclude the changers to the torrc files, to avoid the
 risk of overwriting operators' torrc files.

 I'm sorry the commits here are a bit of a mess.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/17027#comment:22>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list