Hello community, here is the log from the commit of package tor for openSUSE:Factory checked in at 2017-06-30 18:43:17 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/tor (Old) and /work/SRC/openSUSE:Factory/.tor.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Package is "tor" Fri Jun 30 18:43:17 2017 rev:57 rq:507338 version:0.3.0.9 Changes: -------- --- /work/SRC/openSUSE:Factory/tor/tor.changes 2017-06-09 15:57:38.113739764 +0200 +++ /work/SRC/openSUSE:Factory/.tor.new/tor.changes 2017-06-30 18:43:53.789181802 +0200 @@ -1,0 +2,14 @@ +Fri Jun 30 11:53:59 UTC 2017 - astieger@suse.com + +- tor 0.3.0.9: + * CVE-2017-0377: Fix path selection bug that would allow a client + to use a guard that was in the same network family as a chosen + exit relay (bsc#1046845) + * Don't block bootstrapping when a primary bridge is offline and + tor cannot get its descriptor + * When starting with an old consensus, do not add new entry guards + unless the consensus is "reasonably live" (under 1 day old). + * Update geoip and geoip6 to the June 8 2017 Maxmind GeoLite2 + Country database. + +------------------------------------------------------------------- Old: ---- tor-0.3.0.8.tar.gz tor-0.3.0.8.tar.gz.asc New: ---- tor-0.3.0.9.tar.gz tor-0.3.0.9.tar.gz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ tor.spec ++++++ --- /var/tmp/diff_new_pack.4Bftky/_old 2017-06-30 18:43:54.509080544 +0200 +++ /var/tmp/diff_new_pack.4Bftky/_new 2017-06-30 18:43:54.513079981 +0200 @@ -20,7 +20,7 @@ %define torgroup %{name} %define home_dir %{_localstatedir}/lib/empty Name: tor -Version: 0.3.0.8 +Version: 0.3.0.9 Release: 0 Summary: Anonymizing overlay network for TCP (The onion router) License: BSD-3-Clause ++++++ tor-0.3.0.8.tar.gz -> tor-0.3.0.9.tar.gz ++++++ ++++ 14307 lines of diff (skipped)
participants (1)
-
root@hilbert.suse.de