Vulnerability Bulletins

DSA-3741 tor - security update

   
Affected software Debian
 
It was discovered that Tor, a connection-based low-latency anonymouscommunication system, may read one byte past a buffer when parsinghidden service descriptors. This issue may enable a hostile hiddenservice to crash Tor clients depending on hardening options and mallocimplementation.

More info:

https://www.debian.org/security/2016/dsa-3741