[tor-bugs] #22490 [Core Tor/Tor]: Stop using GeoIP country after buf has gone out of scope

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Jun 5 14:12:54 UTC 2017


#22490: Stop using GeoIP country after buf has gone out of scope
-------------------------------------------------+-------------------------
 Reporter:  teor                                 |          Owner:
     Type:  defect                               |         Status:
                                                 |  needs_review
 Priority:  Medium                               |      Milestone:  Tor:
                                                 |  0.3.1.x-final
Component:  Core Tor/Tor                         |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  memory-safety 024-backport           |  Actual Points:  0
  025-backport 026-backport 027-backport         |
  028-backport 029-backport 030-backport         |
Parent ID:                                       |         Points:  0.2
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------
Changes (by nickm):

 * status:  new => needs_review
 * keywords:  memory-safety 029-backport 030-backport =>
     memory-safety 024-backport 025-backport 026-backport 027-backport
     028-backport 029-backport 030-backport
 * actualpoints:   => 0


Comment:

 Looks like this was introduced in a refactoring patch at 6a241ff3ffe7dc1.

 Branch bug22490_024 is a minimal fix.

 Shall we backport this all the way to 0.2.4?  It _is_ undefined behavior,
 and the fix _does_ seem pretty simple.

 (This is not IMO sufficient to force new releases)

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/22490#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list