log uninitialized stack in non-default configuration [CVE-2017-0380]

Related Vulnerabilities: CVE-2017-0380  

Debian Bug report logs - #876221
log uninitialized stack in non-default configuration [CVE-2017-0380]

version graph

Package: tor; Maintainer for tor is Peter Palfrader <weasel@debian.org>; Source for tor is src:tor (PTS, buildd, popcon).

Reported by: Peter Palfrader <weasel@debian.org>

Date: Tue, 19 Sep 2017 19:21:02 UTC

Severity: serious

Tags: fixed-upstream, security, upstream

Found in version tor/0.2.7.2-alpha-1

Fixed in versions 0.2.9.12-1, 0.3.1.7-1

Done: Debian FTP Masters <ftpmaster@ftp-master.debian.org>

Bug is archived. No further changes may be made.

Forwarded to https://bugs.torproject.org/23490

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org:
Bug#876221; Package tor. (Tue, 19 Sep 2017 19:21:04 GMT) (full text, mbox, link).


Acknowledgement sent to Peter Palfrader <weasel@debian.org>:
New Bug report received and forwarded. (Tue, 19 Sep 2017 19:21:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Peter Palfrader <weasel@debian.org>
To: submit@bugs.debian.org
Subject: log uninitialized stack in non-default configuration [CVE-2017-0380]
Date: Tue, 19 Sep 2017 19:20:12 +0000
Package: tor
Severity: serious
Version: 0.2.7.2-alpha-1
Control: forwarded -1 https://bugs.torproject.org/23490

tor could log uninitialized stack when a certain hidden service error occurred
while SafeLogging was disabled.

This is also tracked as TROVE-2017-008 and CVE-2017-0380.

-- 
                            |  .''`.       ** Debian **
      Peter Palfrader       | : :' :      The  universal
 https://www.palfrader.org/ | `. `'      Operating System
                            |   `-    https://www.debian.org/



Set Bug forwarded-to-address to 'https://bugs.torproject.org/23490'. Request was from Peter Palfrader <weasel@debian.org> to submit@bugs.debian.org. (Tue, 19 Sep 2017 19:21:04 GMT) (full text, mbox, link).


Added tag(s) pending. Request was from Peter Palfrader <weasel@debian.org> to control@bugs.debian.org. (Tue, 19 Sep 2017 21:00:03 GMT) (full text, mbox, link).


Added tag(s) upstream and fixed-upstream. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 20 Sep 2017 04:18:02 GMT) (full text, mbox, link).


Reply sent to Debian FTP Masters <ftpmaster@ftp-master.debian.org>:
You have taken responsibility. (Wed, 20 Sep 2017 09:42:10 GMT) (full text, mbox, link).


Notification sent to Peter Palfrader <weasel@debian.org>:
Bug acknowledged by developer. (Wed, 20 Sep 2017 09:42:10 GMT) (full text, mbox, link).


Message #16 received at 876221-done@bugs.debian.org (full text, mbox, reply):

From: Debian FTP Masters <ftpmaster@ftp-master.debian.org>
To: Peter Palfrader <weasel@debian.org>
Subject: tor_0.3.1.7-1_weasel.changes ACCEPTED into unstable
Date: Wed, 20 Sep 2017 09:39:11 +0000
[Message part 1 (application/pgp, inline)]
Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Mon, 18 Sep 2017 23:01:50 +0200
Source: tor
Binary: tor tor-geoipdb
Architecture: source
Version: 0.3.1.7-1
Distribution: unstable
Urgency: medium
Maintainer: Peter Palfrader <weasel@debian.org>
Changed-By: Peter Palfrader <weasel@debian.org>
Description:
 tor        - anonymizing overlay network for TCP
 tor-geoipdb - GeoIP database for Tor
Changes:
 tor (0.3.1.7-1) unstable; urgency=medium
 .
   * New upstream version, upload 0.3.1.x tree to unstable.
   * Build depend on liblzma-dev and libzstd-dev.
Checksums-Sha1:
 4d69471adb52de0fbfa04af3f77c170235f2b266 1800 tor_0.3.1.7-1.dsc
 9a675add1e20ef0eb624c03db71b9f5a506a445d 6058284 tor_0.3.1.7.orig.tar.gz
 4c7c8183f5e747883064352fd6d1b121c6471cba 47818 tor_0.3.1.7-1.diff.gz
Checksums-Sha256:
 4c386f550f8838f7a11adb2cdedf7b5cc120c677f366637f1714d959ef6815c1 1800 tor_0.3.1.7-1.dsc
 1df5dd4894bb2f5e0dc96c466955146353cf33ac50cd997cfc1b28ea3ed9c08f 6058284 tor_0.3.1.7.orig.tar.gz
 6ecdd21021e0eb9139c26abd385b9fc968a5651ee74e34cc2e064938ead84eb3 47818 tor_0.3.1.7-1.diff.gz
Files:
 3d260898dd70fce67e13db0877ebdb2d 1800 net optional tor_0.3.1.7-1.dsc
 ec7c9f588c9e1a42c09bcc097a1e55eb 6058284 net optional tor_0.3.1.7.orig.tar.gz
 fb8ac7369b5e54ac3efdbbff6228a6f7 47818 net optional tor_0.3.1.7-1.diff.gz

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEs4PXhajJL968BgN2hgLIIDhyMx8FAlnCMhsACgkQhgLIIDhy
Mx+8lQgAtpKbXxDsCG382T84kvC0ddIbzFky71Va2iKIcLuUvbzGdNtL1hc6bfTt
zqnHy08vyVtWST1euiwX1sNlQNvSnV34BI3QX95xUXyOXpk6ytX1fcIWzUJO1jZF
Zwo8lk671PNjR7tbHiU5SYqzJOhDIkuySMJjzB4X6765YLkicYjZg3TJhdHADKUq
YXf5SK61LNYMi/80K4H27qJK3YjFgOYEpm22Zf8kT0ayTqgIcRMMt8W3+6POZFNb
qCobV86MPIaJ4796Y34rMycowL6MWTHC3YwoffYTrK803wnq5oT9U7lEI9cNQ7Pz
LDC+rUo5sSejmuqmVOLdq54l50boBg==
=o9gS
-----END PGP SIGNATURE-----


Thank you for your contribution to Debian.




Added tag(s) security. Request was from Peter Palfrader <weasel@debian.org> to control@bugs.debian.org. (Wed, 20 Sep 2017 09:42:14 GMT) (full text, mbox, link).


Marked as fixed in versions 0.3.1.7-1. Request was from Peter Palfrader <weasel@debian.org> to control@bugs.debian.org. (Wed, 20 Sep 2017 09:51:04 GMT) (full text, mbox, link).


Marked as fixed in versions 0.2.9.12-1. Request was from Peter Palfrader <weasel@debian.org> to control@bugs.debian.org. (Tue, 03 Oct 2017 12:15:06 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sun, 10 Dec 2017 07:26:22 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 18:32:28 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.