Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bumped Tor version to 0.4.5.7 #5875

Merged
merged 2 commits into from
Mar 23, 2021
Merged

Bumped Tor version to 0.4.5.7 #5875

merged 2 commits into from
Mar 23, 2021

Conversation

zenmonkeykstop
Copy link
Contributor

@zenmonkeykstop zenmonkeykstop commented Mar 17, 2021

Status

WIP

Description of Changes

Fixes #5873 .

Updates Tor package version downloaded from Tor Project repos from 0.4.5.6 to 0.4.5.7.

This update includes fixes for two DoS attacks, one directly against directory authorities, which does not affect SecureDrop , and one using compromised authorities to launch attacks against any Tor instances, including SecureDrop. Severity for the latter is rated High - it is being tracked as TROVE-2021- 001 in Tor's vulnerability listings and CVE-2021-28089 (pending) in general. There are no recorded cases of it affecting SecureDrop instances so far.

Testing

Deployment

Will be deployed independently to apt.freedom.press and picked up on next nightly update. Users wishing to apply it earlier can do so via cron-apt on Xenial and unattended-upgrades on Focal.

@conorsch
Copy link
Contributor

Marking WIP since we're seeing failures in CI: https://app.circleci.com/pipelines/github/freedomofpress/securedrop/2154/workflows/d7d16659-8006-4cdd-8a2a-65a36c02c5f1/jobs/52504 Based on @zenmonkeykstop's comments out of band, we suspect setuptools version drift to be at fault. Taking a closer look now.

Copy link
Contributor

@conorsch conorsch left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving these changes, along with freedomofpress/securedrop-apt-test#101, where packages of the referenced versions are submitted.

I'm going to hold off on merge here until we verify that CI passes using the new packages. Normally that's as simple as re-running the CI job, but due to ongoing quay.io problems, we may need to wait until tomorrow for a successful CI run.

@conorsch
Copy link
Contributor

Rerunning CI now that Quay is stable again, we should see all tests passing, including the latest version numbers here.

@conorsch conorsch merged commit 012d30e into develop Mar 23, 2021
@rmol rmol deleted the bump-tor-0.4.5.7 branch June 23, 2021 13:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Bump Tor version to 0.4.5.7
2 participants