summaryrefslogtreecommitdiff
path: root/changes
diff options
context:
space:
mode:
authorNick Mathewson <nickm@torproject.org>2021-03-15 09:01:59 -0400
committerNick Mathewson <nickm@torproject.org>2021-03-15 09:01:59 -0400
commit33d1e45a68d251f1543c6a21c0af52c4cd720615 (patch)
tree00416c108a9b8492a78618387059991842cbf288 /changes
parent9c63b3b0c22f67e059d9c9dcb22ce0d8efc0512a (diff)
parent61731e35507fea1c932f80f0849dcae924113df1 (diff)
downloadtor-33d1e45a68d251f1543c6a21c0af52c4cd720615.tar.gz
tor-33d1e45a68d251f1543c6a21c0af52c4cd720615.zip
Merge branch 'maint-0.4.5' into release-0.4.5
Diffstat (limited to 'changes')
-rw-r--r--changes/bug403165
1 files changed, 5 insertions, 0 deletions
diff --git a/changes/bug40316 b/changes/bug40316
new file mode 100644
index 0000000000..cd275b5c9c
--- /dev/null
+++ b/changes/bug40316
@@ -0,0 +1,5 @@
+ o Major bugfixes (security, denial of service):
+ - Fix a bug in appending detached signatures to a pending consensus
+ document that could be used to crash a directory authority.
+ Fixes bug 40316; bugfix on 0.2.2.6-alpha. Tracked as
+ TROVE-2021-002 and CVE-2021-28090.