it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Moritz Muehlenhoff <jmm AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5320-1] tor security update
- Date: Mon, 16 Jan 2023 19:28:46 +0000
- Authentication-results: mail.piratenpartei.de; dkim=none; dmarc=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"
- List-archive: https://lists.debian.org/msgid-search/Y8WlbiySYcaO6I+s AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=0SmIGAjTwrXH1y3TGe5iRuCV9pluQEKY9ZTvJU7/0Vw=; b=Wn J5ibCZCZLxbW+ENqOJeshvvyjyx7RRktsP1YVN5j7U7mx7PccG/I0ZXlpAOR1Fergp3GOCTxZJDnP bMPflHqik9+RWUiToYoliV/Gha4m90FslAETdAvVdtdlaCoGr+oz1HX/o3R1bWXeoJziMTKtlGbYU +PCJwQ5liA91wwDmP5domI7Awe+V1kTZZapV0UQr4eBJubh942WPNifBXiw3ue8xPGJELN1Ul1Pps u5E+KL8bsysEpIVtTN+HEqOa9m1D7oJa8KKzmSnoC4vPloBRg5RO3Ng0hWU7yaSjNTRV4m6UB60fk X1t5yYzqpfebSvSI3JYSFCLDvLTsx1EQ==;
- Old-return-path: <jmm AT seger.debian.org>
- Priority: urgent
- Resent-date: Mon, 16 Jan 2023 19:29:09 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <vb1WkpQZB9K.A.mrE.FWaxjB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5320-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
January 16, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : tor
CVE ID : CVE-2023-23589
A logic error was discovered in the implementation of the "SafeSocks"
option of Tor, a connection-based low-latency anonymous communication
system, which did result in allowing unsafe SOCKS4 traffic to pass.
For the stable distribution (bullseye), this problem has been fixed in
version 0.4.5.16-1.
We recommend that you upgrade your tor packages.
For the detailed security status of tor please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/tor
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIyBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmPFo7EACgkQEMKTtsN8
TjYBiQ/3Z0/GsDkFaQcjChUneEGZwHDjyw1H/0FzOSbAl6KAjCeiPX645IQZ00Ni
lqc+uldH8YdXfbM3K330ld25VOb4F7ETgWqeP2nEGtqgTrYkg0EiQFWOtf+cF80w
kwo+fK+Okq7FKT2ujBNXnZeUcUfwlUfa+Zuo87g9tYU5WNzyl5SB8F13sq9AyWRZ
K/1EKJqpeKhsjPfTM06ee2sEXX8vxMXEKvBtzdk5FonAPU2NLv0Nr+P82aFWUsCr
SpjN0yU4qN6/mv7ePqWrk+OJlBdTi2sNv7Yu7S/kDnmkiBR0UqkL4eQve/+UUlR0
FEVMrzgJKtITT5zLFsmBNHZmx9LDHkAQsNTSefze4SFYSPqykOYvKpF2UmYtwl+w
WcttU/He7RVNiw6WE1i4Du+YOyD9BT3nVC2Aql3hcsKGsOHSxWXWUIXFtG9zIagz
Z/KGLFWS7VnMXO6x3a7lYTjgR0LzZFruCpSyzh5polM9adaR3PBsoVLfUQpq5c2O
WVMEAHbu8hCWPmVLiOnyLo8vTT7lxMwErWNC/fs4WshpDNu2hD+LW8ZZoRpqN2lz
lUAsTaxyTLvDblS/NZM4byHfEcB0yFQEWLEreFyNR9qbgo0/gFrWk6OZdT0odTFV
TeTUDnlf+WnJnwP8KV5OJl5GHvERnpDwPQCxH6UaPoF1BSos8A==
=jzew
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5320-1] tor security update, Moritz Muehlenhoff, 16.01.2023
Archiv bereitgestellt durch MHonArc 2.6.24.