[tor-talk] "EVIL bug" Linux Tor Browser Bundle (2.2.35-8)

Nick Mathewson nickm at alum.mit.edu
Mon Mar 19 15:52:46 UTC 2012

On Mon, Mar 19, 2012 at 10:51 AM,  <ming at tormail.net> wrote:
> https://blog.torproject.org/blog/new-tor-browser-bundles-16
> On March 18th, 2012 Anonymous said:
> "There is an EVIL bug in at least the Linux start-tor-browser script. See
> https://trac.torproject.org/projects/tor/ticket/5417
> A simple error with a simple fix.
> It will log things like domain names to a file in the root of the browser
> bundle."
> *****************************
> Wow, Anonymous! Wow, what an amazing, "bug".
> Linux users, check your Tor Browser Bundle install directory for the file:
> "vidalia-debug-log" and examine it.
> Is a new version with a fix in the works?

It seems that a fix was merged yesterday: see
https://trac.torproject.org/projects/tor/ticket/5417 and

I bet there will be new TBBs out very soon.

In the meantime, Linux users should delete vidalia-debug-log and
symlink it to /dev/null.  (Haven't tested that, but it should work:

  % ln -sf /dev/null /path/to/vidalia-debug-log
  % ls -l /path/to/vidalia-debug-log

  lrwxr-xr-x  1 username  username  9 Mar 19 11:53 vidalia-debug-log
-> /dev/null

IMO, this is a really good reason for us to move to getting enough
automation done so we can have nightly TBB builds and catch this kind
of thing *before* actual releases come out.


More information about the tor-talk mailing list