Bug ID 1167014
Summary VUL-0: CVE-2020-10593: tor: circuit padding memory leak (TROVE-2020-004)
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.1
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee bwiedemann@suse.com
Reporter Andreas.Stieger@gmx.de
QA Contact security-team@suse.de
Found By ---
Blocker ---

https://lists.torproject.org/pipermail/tor-announce/2020-March/000196.html

  o Major bugfixes (circuit padding, memory leak, backport from 0.4.3.3-alpha):
    - Avoid a remotely triggered memory leak in the case that a circuit
      padding machine is somehow negotiated twice on the same circuit.
      Fixes bug 33619; bugfix on 0.4.0.1-alpha. Found by Tobias Pulls.
      This is also tracked as TROVE-2020-004 and CVE-2020-10593.

Fixed in 0.3.5.10, 0.4.1.9, and 0.4.2.7.


You are receiving this mail because: