openSUSE Security Update: Security update for tor ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:0620-1 Rating: moderate References: #1083845 #1083846 Cross-References: CVE-2018-0490 CVE-2018-0491 Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for tor to version 0.3.2.10 fixes security issues and bugs. The following vulnerabilities were fixed: - CVE-2018-0490: remote crash vulnerability against directory authorities (boo#1083845, TROVE-2018-001) - CVE-2018-0491: remote relay crash (boo#1083846, TROVE-2018-002) This new upstream stable version also contains a new system for improved resistance to DoS attacks against relays and various other bug fixes. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Package Hub for SUSE Linux Enterprise 12: zypper in -t patch openSUSE-2018-223=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64): tor-0.3.2.10-14.1 tor-debuginfo-0.3.2.10-14.1 tor-debugsource-0.3.2.10-14.1 References: https://www.suse.com/security/cve/CVE-2018-0490.html https://www.suse.com/security/cve/CVE-2018-0491.html https://bugzilla.suse.com/1083845 https://bugzilla.suse.com/1083846