aboutsummaryrefslogtreecommitdiff
path: root/changes
diff options
context:
space:
mode:
authorNick Mathewson <nickm@torproject.org>2011-06-01 12:12:01 -0400
committerNick Mathewson <nickm@torproject.org>2011-06-06 16:18:06 -0400
commit42e4e156d95a1c28a666a5346d491c4ed71435dd (patch)
tree66e8380b129be449e895fa93b7240f80985e7be8 /changes
parent5afab5ca197112b01135980d6cb3694a4519e3cf (diff)
downloadtor-42e4e156d95a1c28a666a5346d491c4ed71435dd.tar
tor-42e4e156d95a1c28a666a5346d491c4ed71435dd.tar.gz
Detect insanely large circuit build state; don't give its length to rand_int
Diffstat (limited to 'changes')
-rw-r--r--changes/bug33064
1 files changed, 4 insertions, 0 deletions
diff --git a/changes/bug3306 b/changes/bug3306
index b1bb1035c..f868a24af 100644
--- a/changes/bug3306
+++ b/changes/bug3306
@@ -3,3 +3,7 @@
correctly. Previously, it accepted values up to UINT_MAX, but
could return a negative number if given a value above INT_MAX+1.
Found by George Kadianakis. Fixes bug 3306; bugfix on 0.2.2pre14.
+
+ - Avoid a segfault when reading a malformed circuit build state
+ with more than INT_MAX entries. Found by wanoskarnet. Bugfix on
+ 0.2.2.4-alpha.