[tor-commits] [tor/release-0.2.4] Changelog for 0.2.4.27

nickm at torproject.org nickm at torproject.org
Mon Apr 6 13:55:36 UTC 2015


commit 85169a121e3b59d2032281e72e0e14a53b6085a2
Author: Nick Mathewson <nickm at torproject.org>
Date:   Mon Apr 6 09:55:27 2015 -0400

    Changelog for 0.2.4.27
---
 ChangeLog    |   24 ++++++++++++++++++++++++
 ReleaseNotes |   24 ++++++++++++++++++++++++
 2 files changed, 48 insertions(+)

diff --git a/ChangeLog b/ChangeLog
index 5581e82..e0080aa 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,27 @@
+Changes in version 0.2.4.27 - 2015-04-06
+  Tor 0.2.4.27 backports two fixes from 0.2.6.7 for security issues that
+  could be used by an attacker to crash hidden services, or crash clients
+  visiting hidden services. Hidden services should upgrade as soon as
+  possible; clients should upgrade whenever packages become available.
+
+  This release also backports a simple improvement to make hidden
+  services a bit less vulnerable to denial-of-service attacks.
+
+  o Major bugfixes (security, hidden service):
+    - Fix an issue that would allow a malicious client to trigger an
+      assertion failure and halt a hidden service. Fixes bug 15600;
+      bugfix on 0.2.1.6-alpha. Reported by "disgleirio".
+    - Fix a bug that could cause a client to crash with an assertion
+      failure when parsing a malformed hidden service descriptor. Fixes
+      bug 15601; bugfix on 0.2.1.5-alpha. Found by "DonnchaC".
+
+  o Minor features (DoS-resistance, hidden service):
+    - Introduction points no longer allow multiple INTRODUCE1 cells to
+      arrive on the same circuit. This should make it more expensive for
+      attackers to overwhelm hidden services with introductions.
+      Resolves ticket 15515.
+
+
 Changes in version 0.2.4.26 - 2015-03-17
   Tor 0.2.4.26 includes an updated list of directory authorities.  It
   also backports a couple of stability and security bugfixes from 0.2.5
diff --git a/ReleaseNotes b/ReleaseNotes
index ba56dc6..528608c 100644
--- a/ReleaseNotes
+++ b/ReleaseNotes
@@ -3,6 +3,30 @@ This document summarizes new features and bugfixes in each stable release
 of Tor. If you want to see more detailed descriptions of the changes in
 each development snapshot, see the ChangeLog file.
 
+Changes in version 0.2.4.27 - 2015-04-06
+  Tor 0.2.4.27 backports two fixes from 0.2.6.7 for security issues that
+  could be used by an attacker to crash hidden services, or crash clients
+  visiting hidden services. Hidden services should upgrade as soon as
+  possible; clients should upgrade whenever packages become available.
+
+  This release also backports a simple improvement to make hidden
+  services a bit less vulnerable to denial-of-service attacks.
+
+  o Major bugfixes (security, hidden service):
+    - Fix an issue that would allow a malicious client to trigger an
+      assertion failure and halt a hidden service. Fixes bug 15600;
+      bugfix on 0.2.1.6-alpha. Reported by "disgleirio".
+    - Fix a bug that could cause a client to crash with an assertion
+      failure when parsing a malformed hidden service descriptor. Fixes
+      bug 15601; bugfix on 0.2.1.5-alpha. Found by "DonnchaC".
+
+  o Minor features (DoS-resistance, hidden service):
+    - Introduction points no longer allow multiple INTRODUCE1 cells to
+      arrive on the same circuit. This should make it more expensive for
+      attackers to overwhelm hidden services with introductions.
+      Resolves ticket 15515.
+
+
 Changes in version 0.2.4.26 - 2015-03-17
   Tor 0.2.4.26 includes an updated list of directory authorities.  It
   also backports a couple of stability and security bugfixes from 0.2.5



More information about the tor-commits mailing list