Bug 671259 (CVE-2011-0015, CVE-2011-0016, CVE-2011-0427, CVE-2011-0490, CVE-2011-0491, CVE-2011-0492, CVE-2011-0493)
Summary: | CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 tor: multiple security flaws fixed in 0.2.1.29 | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Vincent Danen <vdanen> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | casmls, cassmodiah, lmacken, michael, pwouters, rcvalle, rh-bugzilla, tremble, wnefal+redhatbugzilla |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2013-05-31 03:13:59 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 671263 | ||
Bug Blocks: |
Description
Vincent Danen
2011-01-20 21:42:21 UTC
Fedora currently has 0.2.1.29 in testing, so once those have hit stable, Fedora is taken care of. EPEL5 has quite an old version of tor (0.2.1.19) and is vulnerable to these flaws. Created tor tracking bugs for this issue Affects: epel-5 [bug 671263] F13 and F14 still doesn't contain 0.2.1.29. What is blocking 0.2.1.29? http://koji.fedoraproject.org/koji/buildinfo?buildID=214444 http://koji.fedoraproject.org/koji/buildinfo?buildID=214443 there also 0.2.1.30 packages: http://koji.fedoraproject.org/koji/buildinfo?buildID=234269 http://koji.fedoraproject.org/koji/buildinfo?buildID=234271 Please see bug #705192; we need to update to 0.2.1.30. Thanks. fixed long time ago |