[tor-commits] [tor/release-0.4.0] Add TROVE-2019-001 to changelog for

nickm at torproject.org nickm at torproject.org
Thu Feb 21 15:24:33 UTC 2019

commit feb744f0d488a0e5768385639311f50aab1f4f5d
Author: Nick Mathewson <nickm at torproject.org>
Date:   Thu Feb 21 10:21:10 2019 -0500

    Add TROVE-2019-001 to changelog for
 ChangeLog           | 13 +++++++++++++
 changes/ticket29168 |  5 -----
 2 files changed, 13 insertions(+), 5 deletions(-)

diff --git a/ChangeLog b/ChangeLog
index a99632ed0..8c10b6079 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -3,6 +3,19 @@ Changes in version - 2019-02-21
   bugs from earlier versions, including several that had broken
   backward compatibility.
+  It also includes a fix for a medium-severity security bug affecting Tor
+ and later. All Tor instances running an affected release
+  should upgrade to,,, or
+  o Major bugfixes (cell scheduler, KIST, security):
+    - Make KIST consider the outbuf length when computing what it can
+      put in the outbuf. Previously, KIST acted as though the outbuf
+      were empty, which could lead to the outbuf becoming too full. It
+      is possible that an attacker could exploit this bug to cause a Tor
+      client or relay to run out of memory and crash. Fixes bug 29168;
+      bugfix on This issue is also being tracked as
+      TROVE-2019-001 and CVE-2019-8955.
   o Major bugfixes (networking):
     - Gracefully handle empty username/password fields in SOCKS5
       username/password auth messsage and allow SOCKS5 handshake to
diff --git a/changes/ticket29168 b/changes/ticket29168
deleted file mode 100644
index 65c5232f6..000000000
--- a/changes/ticket29168
+++ /dev/null
@@ -1,5 +0,0 @@
-  o Major bugfixes (cell scheduler, KIST):
-    - Make KIST to always take into account the outbuf length when computing
-      what we can actually put in the outbuf. This could lead to the outbuf
-      being filled up and thus a possible memory DoS vector. TROVE-2019-001.
-      Fixes bug 29168; bugfix on

More information about the tor-commits mailing list