[Bug 878486] New: tor upgrade to 0.2.4.22
https://bugzilla.novell.com/show_bug.cgi?id=878486 https://bugzilla.novell.com/show_bug.cgi?id=878486#c0 Summary: tor upgrade to 0.2.4.22 Classification: openSUSE Product: openSUSE 13.1 Version: Final Platform: All OS/Version: openSUSE 13.1 Status: NEW Severity: Normal Priority: P5 - None Component: Security AssignedTo: security-team@suse.de ReportedBy: Andreas.Stieger@gmx.de QAContact: qa-bugs@suse.de Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (X11; Linux i686; rv:29.0) Gecko/20100101 Firefox/29.0 openSUSE:12.3:Update has 0.2.3.25 openSUSE:13.1:Update has 0.2.3.25 network, openSUSE:Factory are on 0.2.4.21 (->22) The current stable release is 0.2.4.22. Dear maintenance team, as per maintenance policy, (http://en.opensuse.org/openSUSE:Maintenance_policy) please approve version update from 0.2.3.x to 0.2.4.x for 12.3 and 13.1. I give the following reasons: * Upstream is no longer maintaining 0.2.3.x * Important fixes for security issues (cyphersuite changes, heartbleed openSSL remediations) are only available in 0.2.4.x * upstream discourages use of 0.2.3.x * fixes are complex to backport * tor is a leaf package Reproducible: Couldn't Reproduce -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=878486 https://bugzilla.novell.com/show_bug.cgi?id=878486#c Andreas Stieger <Andreas.Stieger@gmx.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |NEEDINFO InfoProvider| |maintenance@opensuse.org -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=878486 https://bugzilla.novell.com/show_bug.cgi?id=878486#c1 Benjamin Brunner <bbrunner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- InfoProvider|maintenance@opensuse.org |security-team@suse.de --- Comment #1 from Benjamin Brunner <bbrunner@suse.com> 2014-05-19 13:37:12 CEST --- A version-update shouldn't be a problem, but after it also includes security-fixes, I changed needinfo to our security-team. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=878486 https://bugzilla.novell.com/show_bug.cgi?id=878486#c2 Sebastian Krahmer <krahmer@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |NEW InfoProvider|security-team@suse.de | --- Comment #2 from Sebastian Krahmer <krahmer@suse.com> 2014-05-19 13:26:33 UTC --- +1 from security side -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=878486 https://bugzilla.novell.com/show_bug.cgi?id=878486#c Andreas Stieger <Andreas.Stieger@gmx.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium Status|NEW |ASSIGNED CC| |security-team@suse.de AssignedTo|security-team@suse.de |Andreas.Stieger@gmx.de -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=878486 https://bugzilla.novell.com/show_bug.cgi?id=878486#c3 Andreas Stieger <Andreas.Stieger@gmx.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|ASSIGNED |NEEDINFO CC| |maintenance@opensuse.org InfoProvider| |security-team@suse.de --- Comment #3 from Andreas Stieger <Andreas.Stieger@gmx.de> 2014-05-19 22:42:05 UTC --- Please review maintenance request for openSUSE 12.3 and 13.1, making the package identical to network / tor (modulo .changes) https://build.opensuse.org/request/show/234771 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=878486 https://bugzilla.novell.com/show_bug.cgi?id=878486#c Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Status Whiteboard| |obs:running:2829:moderate -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=878486 https://bugzilla.novell.com/show_bug.cgi?id=878486#c4 Sebastian Krahmer <krahmer@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEEDINFO |ASSIGNED InfoProvider|security-team@suse.de | --- Comment #4 from Sebastian Krahmer <krahmer@suse.com> 2014-05-28 08:16:25 UTC --- released -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=878486 https://bugzilla.novell.com/show_bug.cgi?id=878486#c5 Sebastian Krahmer <krahmer@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|ASSIGNED |RESOLVED CC| |krahmer@suse.com Resolution| |FIXED --- Comment #5 from Sebastian Krahmer <krahmer@suse.com> 2014-05-28 08:16:35 UTC --- . -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=878486 https://bugzilla.novell.com/show_bug.cgi?id=878486#c6 --- Comment #6 from Swamp Workflow Management <swamp@suse.de> 2014-05-28 09:04:39 UTC --- openSUSE-SU-2014:0719-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 878486 CVE References: CVE-2014-0160 Sources used: openSUSE 13.1 (src): tor-0.2.4.22-5.8.1 openSUSE 12.3 (src): tor-0.2.4.22-2.8.1 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
http://bugzilla.novell.com/show_bug.cgi?id=878486 Swamp Workflow Management <swamp@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Whiteboard|obs:running:2829:moderate | -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com