[tor-bugs] #22490 [Core Tor/Tor]: Stop using GeoIP country after buf has gone out of scope
Tor Bug Tracker & Wiki
blackhole at torproject.org
Mon Jun 5 14:12:54 UTC 2017
#22490: Stop using GeoIP country after buf has gone out of scope
-------------------------------------------------+-------------------------
Reporter: teor | Owner:
Type: defect | Status:
| needs_review
Priority: Medium | Milestone: Tor:
| 0.3.1.x-final
Component: Core Tor/Tor | Version:
Severity: Normal | Resolution:
Keywords: memory-safety 024-backport | Actual Points: 0
025-backport 026-backport 027-backport |
028-backport 029-backport 030-backport |
Parent ID: | Points: 0.2
Reviewer: | Sponsor:
-------------------------------------------------+-------------------------
Changes (by nickm):
* status: new => needs_review
* keywords: memory-safety 029-backport 030-backport =>
memory-safety 024-backport 025-backport 026-backport 027-backport
028-backport 029-backport 030-backport
* actualpoints: => 0
Comment:
Looks like this was introduced in a refactoring patch at 6a241ff3ffe7dc1.
Branch bug22490_024 is a minimal fix.
Shall we backport this all the way to 0.2.4? It _is_ undefined behavior,
and the fix _does_ seem pretty simple.
(This is not IMO sufficient to force new releases)
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/22490#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list