Skip to content
  • Nick Mathewson's avatar
    Fix detection of point to insert signatures on a pending consensus. · 890ae4fb
    Nick Mathewson authored
    We were looking for the first instance of "directory-signature "
    when instead the correct behavior is to look for the first instance
    of "directory-signature " at the start of a line.
    
    Unfortunately, this can be exploited as to crash authorities while
    they're voting.
    
    Fixes #40316; bugfix on 0.2.2.4-alpha.  This is TROVE-2021-002,
    also tracked as CVE-2021-28090.
    890ae4fb