aboutsummaryrefslogtreecommitdiff
path: root/ChangeLog
diff options
context:
space:
mode:
authorNick Mathewson <nickm@torproject.org>2012-10-25 10:32:20 -0400
committerNick Mathewson <nickm@torproject.org>2012-10-25 10:32:20 -0400
commitb6e0236fa20d001ba3f940caf37b5434bf76401a (patch)
treea753ad062361bdada0523dde40d576f123e1cf80 /ChangeLog
parent48cdcc9d4ad12b7c57c8ac578db5961da27fde85 (diff)
downloadtor-b6e0236fa20d001ba3f940caf37b5434bf76401a.tar
tor-b6e0236fa20d001ba3f940caf37b5434bf76401a.tar.gz
Fold in changelog item; draft blurb for 0.2.4.5-alpha
Diffstat (limited to 'ChangeLog')
-rw-r--r--ChangeLog26
1 files changed, 18 insertions, 8 deletions
diff --git a/ChangeLog b/ChangeLog
index f312b22b2..1a55d47ea 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,9 +1,20 @@
Changes in version 0.2.4.5-alpha - 2012-10-2?
- o Major bugfixes (also in 0.2.3.24-rc):
+ Tor 0.2.3.24-rc comes hard at the heels of 0.2.4.4-alpha, to fix two
+ important security vulnerabilities that could lead to remotely
+ triggerable relay crashes, fixes a major bug that was preventing
+ clients from choosing good exit nodes, and refactor some of our code.
+
+ o Major bugfixes (security, also in 0.2.3.24-rc):
+ - Fix a group of remotely triggerable assertion failures related to
+ incorrect link protocol negotiation. Found, diagnosed, and fixed
+ by "some guy from France." Fix for CVE-2012-2250; bugfix on
+ 0.2.3.6-alpha.
- Fix a denial of service attack by which any directory authority
could crash all the others, or by which a single v2 directory
authority could crash everybody downloading v2 directory
information. Fixes bug 7191; bugfix on 0.2.0.10-alpha.
+
+ o Major bugfixes (also in 0.2.3.24-rc):
- When parsing exit policy summaries from microdescriptors, we had
previously been ignoring the last character in each one, so that
"accept 80,443,8080" would be treated by clients as indicating
@@ -19,18 +30,17 @@ Changes in version 0.2.4.5-alpha - 2012-10-2?
an exit relay would allow exiting to an internal address. Fixes
bug 7190; bugfix on 0.2.3.1-alpha.
- o Code simplification and refactoring:
- - Start using OpenBSD's implementation of queue.h (originally by Niels
- Provos).
- - Move the entry node code from circuitbuild.c to its own file.
- - Move the circuit build timeout tracking code from circuitbuild.c
- to its own file.
-
o Minor bugfixes:
- Only disable TLS session ticket support when running as a TLS
server. This keeps clients harder to distinguish from regular firefox
connections. Fixes bug 7189; bugfix on Tor 0.2.3.23-rc.
+ o Code simplification and refactoring:
+ - Start using OpenBSD's implementation of queue.h (originally by
+ Niels Provos).
+ - Move the entry node code from circuitbuild.c to its own file.
+ - Move the circuit build timeout tracking code from circuitbuild.c
+ to its own file.
Changes in version 0.2.4.4-alpha - 2012-10-20