]> git.ipfire.org Git - thirdparty/tor.git/commit
Discard extraneous renegotiation attempts in the v3 link protocol
authorNick Mathewson <nickm@torproject.org>
Tue, 16 Oct 2012 16:55:50 +0000 (12:55 -0400)
committerNick Mathewson <nickm@torproject.org>
Wed, 17 Oct 2012 23:18:16 +0000 (19:18 -0400)
commitf357ef9dccccfb5ce2408dbd5f8456de02bac895
treecfd709e594c28e4c4f73fd3bbb48ccd51b98f6c1
parente2549c3b745313d6647c7e1d05025a84e1d33873
Discard extraneous renegotiation attempts in the v3 link protocol

Failure to do so left us open to a remotely triggerable assertion
failure. Fixes CVE-2012-2249; bugfix on 0.2.3.6-alpha. Reported by
"some guy from France".
changes/cve-2012-2249 [new file with mode: 0644]
src/or/command.c
src/or/connection_or.c
src/or/connection_or.h