tor: security bump to 0.2.8.12
authorPeter Korsgaard <peter@korsgaard.com>
Tue, 20 Dec 2016 13:02:37 +0000 (14:02 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Wed, 21 Dec 2016 06:29:39 +0000 (07:29 +0100)
Fixes CVE-2016-1254 - One byte past an allocated buffer read while parsing
hidden service descriptors:

https://blog.torproject.org/blog/tor-02812-released

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/tor/tor.hash
package/tor/tor.mk

index b13fc4a64c071565cd254c4e140ff56c8e16f786..4fdb82c67fa822989258ad386564243bafd1c0c7 100644 (file)
@@ -1,2 +1,2 @@
 # Locally computed
-sha256 c88b8c57b34ebf44b731df5d68f73eb6b6708bcf4e42cf7b4817fd4e304c9c4d  tor-0.2.8.10.tar.gz
+sha256 b35748f2839cf8ce9910b677ea873463495ac88689244c007ed038f6887f4aaf  tor-0.2.8.12.tar.gz
index 4f335228d39c26388067140a2959d18b044e5d8c..5606cc2bf607f94e1f8b709829ecbbe2d2110b7a 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-TOR_VERSION = 0.2.8.10
+TOR_VERSION = 0.2.8.12
 TOR_SITE = https://dist.torproject.org
 TOR_LICENSE = BSD-3c
 TOR_LICENSE_FILES = LICENSE