1. 02 Apr, 2010 1 commit
  2. 11 Mar, 2010 1 commit
  3. 09 Mar, 2010 2 commits
  4. 08 Mar, 2010 1 commit
  5. 07 Mar, 2010 2 commits
  6. 04 Mar, 2010 1 commit
    • Nick Mathewson's avatar
      Apply Roger's bug 1269 fix. · 3ff09239
      Nick Mathewson authored
      From http://archives.seul.org/tor/relays/Mar-2010/msg00006.html :
         As I understand it, the bug should show up on relays that don't set
         Address to an IP address (so they need to resolve their Address
         line or their hostname to guess their IP address), and their
         hostname or Address line fails to resolve -- at that point they'll
         pick a random 4 bytes out of memory and call that their address. At
         the same time, relays that *do* successfully resolve their address
         will ignore the result, and only come up with a useful address if
         their interface address happens to be a public IP address.
  7. 01 Mar, 2010 3 commits
  8. 27 Feb, 2010 2 commits
    • Nick Mathewson's avatar
      Fix a consensus-extension bug found by outofwords · 27a8a56e
      Nick Mathewson authored
      When the bandwidth-weights branch added the "directory-footer"
      token, and began parsing the directory footer at the first
      occurrence of "directory-footer", it made it possible to fool the
      parsing algorithm into accepting unsigned data at the end of a
      consensus or vote.  This patch fixes that bug by treating the footer
      as starting with the first "directory-footer" or the first
      "directory-signature", whichever comes first.
    • Sebastian Hahn's avatar
      Properly handle non-terminated strings · b67657bd
      Sebastian Hahn authored
      Treat strings returned from signed_descriptor_get_body_impl() as not
      NUL-terminated. Since the length of the strings is available, this is
      not a big problem.
      Discovered by rieo.
  9. 26 Feb, 2010 3 commits
    • Sebastian Hahn's avatar
      Proper NULL checking in circuit_list_path_impl() · 86828e20
      Sebastian Hahn authored
      Another dereference-then-NULL-check sequence. No reports of this bug
      triggered in the wild. Fixes bugreport 1256.
      Thanks to ekir for discovering and reporting this bug.
    • Sebastian Hahn's avatar
      Proper NULL checking for hsdesc publication · f36c36f4
      Sebastian Hahn authored
      Fix a dereference-then-NULL-check sequence. This bug wasn't triggered
      in the wild, but we should fix it anyways in case it ever happens.
      Also make sure users get a note about this being a bug when they
      see it in their log.
      Thanks to ekir for discovering and reporting this bug.
    • Sebastian Hahn's avatar
      Zero a cipher completely before freeing it · a9802d33
      Sebastian Hahn authored
      We used to only zero the first ptrsize bytes of the cipher. Since
      cipher is large enough, we didn't zero too many bytes. Discovered
      and fixed by ekir. Fixes bug 1254.
  10. 25 Feb, 2010 1 commit
    • Sebastian Hahn's avatar
      Restrict PerConnBWRate|Burst to INT32_MAX, update manpage · 2917c059
      Sebastian Hahn authored
      All other bandwidthrate settings are restricted to INT32_MAX, but
      this check was forgotten for PerConnBWRate and PerConnBWBurst. Also
      update the manpage to reflect the fact that specifying a bandwidth
      in terabytes does not make sense, because that value will be too
  11. 23 Feb, 2010 4 commits
  12. 22 Feb, 2010 5 commits
  13. 21 Feb, 2010 1 commit
  14. 19 Feb, 2010 1 commit
    • Sebastian Hahn's avatar
      Make the DNSPort option work with libevent 2.x · 408a828b
      Sebastian Hahn authored
      We need to use evdns_add_server_port_with_base() when configuring
      our DNS listener, because libevent segfaults otherwise. Add a macro
      in compat_libevent.h to pick the correct implementation depending
      on the libevent version.
      Fixes bug 1143, found by SwissTorExit
  15. 18 Feb, 2010 4 commits
  16. 16 Feb, 2010 1 commit
  17. 13 Feb, 2010 2 commits
  18. 12 Feb, 2010 2 commits
  19. 09 Feb, 2010 1 commit
  20. 08 Feb, 2010 2 commits