[tor-bugs] #23490 [Core Tor/Tor]: Fix TROVE-2017-008: Stack disclosure in hidden services logs when SafeLogging disabled

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Sep 18 13:39:06 UTC 2017


#23490: Fix TROVE-2017-008: Stack disclosure in hidden services logs when
SafeLogging disabled
------------------------------------------+--------------------------------
 Reporter:  nickm                         |          Owner:  nickm
     Type:  defect                        |         Status:  merge_ready
 Priority:  High                          |      Milestone:  Tor:
                                          |  0.3.1.x-final
Component:  Core Tor/Tor                  |        Version:  Tor:
                                          |  0.2.7.2-alpha
 Severity:  Normal                        |     Resolution:
 Keywords:  trove-2017-008 CVE-2017-0380  |  Actual Points:
Parent ID:                                |         Points:
 Reviewer:                                |        Sponsor:
------------------------------------------+--------------------------------

Comment (by nickm):

 I have attached two patches here: one is the fix for 028 and 029, and the
 other is the fix for 030 and later.

 Now, time to announce the issue and put out releases.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/23490#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list