Warning to NoReply.org DEB Package Users

Kyle Williams kyle.kwilliams at gmail.com
Fri Aug 10 22:06:36 UTC 2007


This is not true.  The affects of the bug are very sever, and it DOES NOT
require the config to be saved!  An attacker could still cause you to loose
your anonymity.
UPDATE, UPDATE, UPDATE.


On 8/10/07, Florian Reitmeir <florian at reitmeir.org> wrote:
>
> On Fri, 10 Aug 2007, Ringo Kamens wrote:
>
> > As you know, a major security vulnerability was just patched with the
> > 0.1.2.16 release. I have been using the noreply.org deb packages but
> > they didn't update to the newest version (at least not under amd64
> > feisty). If you are in my situation you can compile from source or
> > disable your controlport and wait out the storm until a new version is
> > released. Is the package maintainer busy or..?
> > Comrade Ringo Kamens
>
> the last security issue, is no issue on debian linux, because on debian
> Tor
> can't write its config file. And  the packager is on holidays in
> Finowurth,
> unil sunday.
>
> --
> Florian Reitmeir
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.torproject.org/pipermail/tor-talk/attachments/20070810/923c43f4/attachment.htm>


More information about the tor-talk mailing list