aboutsummaryrefslogtreecommitdiff
path: root/changes
diff options
context:
space:
mode:
authorDavid Goulet <dgoulet@torproject.org>2023-01-12 10:52:35 -0500
committerDavid Goulet <dgoulet@torproject.org>2023-01-12 10:52:35 -0500
commit0df4083299970674b4f399d3d85c6eab22cb8c7d (patch)
tree08a55c71fc60445018a2ad2e42f3547ac8cd32bf /changes
parentf2e9ce72d62c4057b32a524ad032b86dffa9a995 (diff)
parent7b83e336ec4a1d137d6400f4d501c9a73835e34d (diff)
downloadtor-0df4083299970674b4f399d3d85c6eab22cb8c7d.tar.gz
tor-0df4083299970674b4f399d3d85c6eab22cb8c7d.zip
Merge branch 'maint-0.4.5' into maint-0.4.7
Diffstat (limited to 'changes')
-rw-r--r--changes/ticket407305
1 files changed, 5 insertions, 0 deletions
diff --git a/changes/ticket40730 b/changes/ticket40730
new file mode 100644
index 0000000000..f6d4c9de3b
--- /dev/null
+++ b/changes/ticket40730
@@ -0,0 +1,5 @@
+ o Major bugfixes (TROVE-2022-002, client):
+ - The SafeSocks option had its logic inverted for SOCKS4 and SOCKS4a. It
+ would let the unsafe SOCKS4 pass but not the safe SOCKS4a one. This is
+ TROVE-2022-002 which was reported on Hackerone by "cojabo". Fixes bug
+ 40730; bugfix on 0.3.5.1-alpha.