Skip to content
GitLab
Menu
Projects
Groups
Snippets
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in
Toggle navigation
Menu
Open sidebar
The Tor Project
Core
Tor
Commits
a6533af9
Commit
a6533af9
authored
Mar 15, 2021
by
Nick Mathewson
👁
Browse files
Merge branch 'maint-0.4.4' into maint-0.4.5
parents
7c5a67cc
2eb900f7
Changes
2
Hide whitespace changes
Inline
Side-by-side
changes/ticket40286_minimal
View file @
a6533af9
o Major bugfixes (denial of service):
o Major bugfixes (
security,
denial of service):
- Disable the dump_desc() function that we used to dump unparseable
information to disk. It was called incorrectly in several places,
in a way that could lead to excessive CPU usage.
Fixes bug 40286; bugfix on 0.2.2.1-alpha.
in a way that could lead to excessive CPU usage. Fixes bug 40286;
bugfix on 0.2.2.1-alpha. This bug is also tracked as
TROVE-2021-001 and CVE-2021-28089.
src/feature/dirparse/unparseable.c
View file @
a6533af9
...
...
@@ -498,8 +498,11 @@ dump_desc,(const char *desc, const char *type))
tor_assert
(
desc
);
tor_assert
(
type
);
#ifndef TOR_UNIT_TESTS
/* On older versions of Tor we are disabling this function, since it
* can be called with strings that are far too long. */
/* For now, we are disabling this function, since it can be called with
* strings that are far too long. We can turn it back on if we fix it
* someday, but we'd need to give it a length argument. A likelier
* resolution here is simply to remove this module entirely. See tor#40286
* for background. */
if
(
1
)
return
;
#endif
...
...
Write
Preview
Supports
Markdown
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment