Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Status
WIP
Description of Changes
Fixes #5873 .
Updates Tor package version downloaded from Tor Project repos from 0.4.5.6 to 0.4.5.7.
This update includes fixes for two DoS attacks, one directly against directory authorities, which does not affect SecureDrop , and one using compromised authorities to launch attacks against any Tor instances, including SecureDrop. Severity for the latter is rated High - it is being tracked as TROVE-2021- 001 in Tor's vulnerability listings and CVE-2021-28089 (pending) in general. There are no recorded cases of it affecting SecureDrop instances so far.
Testing
Deployment
Will be deployed independently to apt.freedom.press and picked up on next nightly update. Users wishing to apply it earlier can do so via
cron-apt
on Xenial andunattended-upgrades
on Focal.