{
  "schema_version": "1.7.0",
  "id": "MGASA-2020-0442",
  "published": "2020-12-03T09:54:38Z",
  "modified": "2020-12-03T09:13:16Z",
  "summary": "Updated tor package fixes security vulnerabilities",
  "details": "When completing a channel, relays now check more thoroughly to make sure that\nit matches any pending circuits before attaching those circuits. Previously,\naddress correctness and Ed25519 identities were not checked in this case, but\nonly when extending circuits on an existing channel (TROVE-2020-005).\n\nChannels using obsolete versions of the Tor link protocol are no longer allowed\nto circumvent address-canonicity checks. This is only a minor issue, since\nsuch channels have no way to set ed25519 keys, and therefore should always be\nrejected for circuits that specify ed25519 identities (tor#40081).\n\nThe tor package has been updated to version 0.3.5.12, fixing these issues and\nseveral other bugs.  See the upstream ChangeLog for details.\n",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2020-0442.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=27606"
    },
    {
      "type": "WEB",
      "url": "https://gitweb.torproject.org/tor.git/tree/ChangeLog?h=tor-0.3.5.12"
    },
    {
      "type": "WEB",
      "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2HALCW6KZMSIIXVTNHTNUQPBOYYMU5LL/"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:7",
        "name": "tor",
        "purl": "pkg:rpm/mageia/tor?arch=source&distro=mageia-7"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.3.5.12-1.mga7"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
