ArchLinux: 201504-7: tor: multiple issues
Summary
CVE-2015-2928
"disgleirio" discovered that a malicious client could trigger an
assertion failure in a Tor instance providing a hidden service,
thus rendering the service inaccessible.
CVE-2015-2929
"DonnchaC" discovered that Tor clients would crash with an
assertion failure upon parsing specially crafted hidden service
descriptors.
Resolution
Upgrade to 0.2.5.12-1
# pacman -Syu "tor>=0.2.5.12-1"
The problem has been fixed upstream in version 0.2.5.12.
References
https://gitlab.torproject.org/legacy/trac/-/issues/15600 https://gitlab.torproject.org/legacy/trac/-/issues/15601 https://seclists.org/oss-sec/2015/q2/56
Workaround
None.