tor 0.4.8.18 CVE-2025-4444 boo#1250101 #1

Manually merged
anag_factory merged 11 commits from :leap-16.0 into leap-16.0 2025-09-24 11:31:43 +02:00
8 changed files with 65 additions and 23 deletions

View File

@@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:ca7cc735d98e3747b58f2f3cc14f804dd789fa0fb333a84dcb6bd70adbb8c874
size 9687430

View File

@@ -1 +0,0 @@
ca7cc735d98e3747b58f2f3cc14f804dd789fa0fb333a84dcb6bd70adbb8c874 tor-0.4.8.12.tar.gz

View File

@@ -1,18 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQEzBAABCAAdFiEEt0QX7d8irJ+ekPSRQuhqKhH0jTYFAmZhuq0ACgkQQuhqKhH0
jTYZXAf+J26VUvM2M1DsjeUAMOZPEtNsQ0voIN9jeXFHUt7p3tqa2aBe8gJ5IREC
MtFK6MJLjJEHf6javbwoZuXXQ+xepJftPdJ9AR2bGlTConWE0VNVvfigawFHyKZn
Sdt6JyB2AesWl0HLIZnOXeSLy8JA12s/HPWtt8Fsf94drZwQsSl+WQGHr787JugF
aYmNRR4L+y46xL5HXbJ8KTc/UKPNlT+1vvwoAisofOQywrIJZGFsKpaowNiW9RWi
MXUdjmPjKJZ8vn+FQG0ZOmahUWMOMYIt6fWmkttI5KF6HajtGNTG4A+A5+QMBoif
N/VyJsISI2beHBAgAgPNGsXAa0FsIA==
=2gNt
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQRRQQJFTQqH2wdnoeu+agUxwYqReQUCZmHEggAKCRC+agUxwYqR
eVRoAP0SI+tzoCS06Pf1EJ0Mvea/ACIDZ5+XCaf9U0urRciMhgEA4BjvVG7I2cD8
vGcxbkRtg4h9vZTr8rhdtSczdo3KYAY=
=C9WI
-----END PGP SIGNATURE-----

3
tor-0.4.8.18.tar.gz Normal file
View File

@@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:4aea6c109d4eff4ea2bafb905a7e6b0a965d14fe856214b02fcd9046b4d93af8
size 10139317

View File

@@ -0,0 +1 @@
4aea6c109d4eff4ea2bafb905a7e6b0a965d14fe856214b02fcd9046b4d93af8 tor-0.4.8.18.tar.gz

View File

@@ -0,0 +1,18 @@
-----BEGIN PGP SIGNATURE-----
iQEzBAABCAAdFiEEt0QX7d8irJ+ekPSRQuhqKhH0jTYFAmjJhoIACgkQQuhqKhH0
jTbmFwf/bm1hykDFLO7QgqL8nMd1Zri0LlTzWUhdFzi8XY6QFb/X0qth+nI3IZnx
A6zQkqGgOyJPK871QJDvSttQSbNqqEL4Ks3R5ImTtrlkLJitAbYuenVuXs5Ul+x6
SlfBEAYfe/1OgDnZSe13bAiL+1hJNMxyh8vpu4fcLbQxTZk+dCobjC7V6TlzBvsJ
dMLEQs+Fa+nZx5aol8Asahx7CcPSZdhyTIrxaW7fzQWrOSv4Dnc3EF+XwXDPN2+L
s23/W/gFod2eacyZQbDaxrQT8r0Q9FraNlrl/DDIk9V5ZP8B1bi1sO40oVIVz0fv
jcck9GPY05lM8qJ9kThHaDn7bfjgiw==
=tx5R
-----END PGP SIGNATURE-----
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQRRQQJFTQqH2wdnoeu+agUxwYqReQUCaMmHfgAKCRC+agUxwYqR
eZgcAP9bh1iYOvgWRfl4MT1rWM2IwEm6eAj2I1/ONK0onQhNjgEA0F45K7P8Q98q
Omptk4nxTslHZ75z01TVdFv7rvVdLgo=
=41Rz
-----END PGP SIGNATURE-----

View File

@@ -1,3 +1,44 @@
-------------------------------------------------------------------
Wed Sep 17 06:19:42 UTC 2025 - Bernhard Wiedemann <bwiedemann@suse.de>
- 0.4.8.18
* CVE-2025-4444: onion service descriptor resource consumption
issue (boo#1250101)
-------------------------------------------------------------------
Tue Jul 1 03:12:54 UTC 2025 - Bernhard Wiedemann <bwiedemann@suse.com>
- 0.4.8.17
* Minor features and bugfixes
* use quantum-resistant MLKEM-768 cipher
-------------------------------------------------------------------
Mon Apr 21 16:20:45 UTC 2025 - Andreas Stieger <andreas.stieger@gmx.de>
- tor 0.4.8.16
* fix typo in a directory authority rule file
* fix a sandbox issue for bandwidth authority and a conflux issue
on the control port
* client fix about relay flag usage
-------------------------------------------------------------------
Wed Feb 5 18:26:41 UTC 2025 - Bernhard Wiedemann <bwiedemann@suse.com>
- tor 0.4.8.14
* bugfix for onion service directory cache
* test-network now unconditionally includes IPv6
* Regenerate fallback directories 2025-02-05
* Update the geoip files to 2025-02-05
* Fix a pointer free
-------------------------------------------------------------------
Fri Dec 27 21:55:57 UTC 2024 - Andreas Stieger <andreas.stieger@gmx.de>
- tor 0.4.8.13
* Conflux related client circuit building performance bugfix
* Fix minor memory leaks
* Add STATUS TYPE=version handler for Pluggable Transport
-------------------------------------------------------------------
Tue Jun 11 10:05:46 UTC 2024 - Bernhard Wiedemann <bwiedemann@suse.com>

View File

@@ -2,6 +2,7 @@
# spec file for package tor
#
# Copyright (c) 2024 SUSE LLC
# Copyright (c) 2025 Andreas Stieger <Andreas.Stieger@gmx.de>
#
# All modifications and additions to the file contributed by third parties
# remain the property of their copyright owners, unless otherwise agreed
@@ -20,7 +21,7 @@
%define torgroup %{name}
%define home_dir %{_localstatedir}/lib/empty
Name: tor
Version: 0.4.8.12
Version: 0.4.8.18
Release: 0
Summary: Anonymizing overlay network for TCP (The onion router)
License: BSD-3-Clause