Bug 1216873

Summary: VUL-0: tor: crash during handshake with a remote relay (TROVE-2023-004 )
Product: [openSUSE] openSUSE Distribution Reporter: Andreas Stieger <Andreas.Stieger>
Component: SecurityAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: E-mail List <qa-bugs>
Severity: Normal    
Priority: P3 - Medium CC: bwiedemann
Version: Leap 15.5   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Andreas Stieger 2023-11-03 20:47:13 UTC
It was discovered that tor before 0.4.8.8 compiled with OpenSSL can crash during handshake with a remote relay.

References:
https://gitlab.torproject.org/tpo/core/tor/-/commit/7aa496a2e057bb7c3cc284a04a1a4d2941c304f1
https://gitlab.torproject.org/tpo/core/tor/-/issues/40874
https://gitlab.torproject.org/tpo/core/tor/-/issues/40880
Comment 1 OBSbugzilla Bot 2023-11-03 21:35:03 UTC
This is an autogenerated message for OBS integration:
This bug (1216873) was mentioned in
https://build.opensuse.org/request/show/1123277 Backports:SLE-15-SP4+Backports:SLE-15-SP5 / tor
Comment 2 OBSbugzilla Bot 2023-11-10 05:35:01 UTC
This is an autogenerated message for OBS integration:
This bug (1216873) was mentioned in
https://build.opensuse.org/request/show/1124759 Backports:SLE-15-SP6 / tor
https://build.opensuse.org/request/show/1124760 Backports:SLE-12+Backports:SLE-15-SP4+Backports:SLE-15-SP5 / tor
Comment 3 Marcus Meissner 2023-11-10 14:05:06 UTC
openSUSE-SU-2023:0361-1: An update that contains security fixes can now be installed.

Category: security (moderate)
Bug References: 1216873
CVE References: 
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    tor-0.4.8.8-bp155.2.3.1
openSUSE Backports SLE-15-SP4 (src):    tor-0.4.8.8-bp154.2.15.1
Comment 4 Marcus Meissner 2023-11-13 14:10:46 UTC
done