Path to this page:
Subject: CVS commit: pkgsrc/net/tor
From: Matthias Drochner
Date: 2011-01-17 15:06:54
Message id: 20110117140654.3DCE3175DD@cvs.netbsd.org
Log Message:
update to 0.2.1.29
changes:
-Fix a heap overflow (probably allows remote code execution)
(CVE-2011-0427)
-Prevent a denial-of-service attack by disallowing any
zlib-compressed data whose compression factor is implausibly
high
-Zero out a few more keys in memory before freeing them
-bugfixes
-Update to the January 1 2011 Maxmind GeoLite Country db
-Introduce output size checks on all of our decryption functions
Files: