Re: [tor-relays] Advisory: Stack disclosure in hidden services logs when SafeLogging disabled

2017-09-18 Thread Nick Mathewson
On Mon, Sep 18, 2017 at 1:19 PM, Toralf Förster wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On 09/18/2017 03:41 PM, Nick Mathewson wrote: >> This bug can only happen when the SafeLogging option is disabled, >> and SafeLogging is enabled by default. If you have not disabled

Re: [tor-relays] Advisory: Stack disclosure in hidden services logs when SafeLogging disabled

2017-09-18 Thread Toralf Förster
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 09/18/2017 03:41 PM, Nick Mathewson wrote: > This bug can only happen when the SafeLogging option is disabled, > and SafeLogging is enabled by default. If you have not disabled > SafeLogging, then you should be fine. Which should not hinde

[tor-relays] Advisory: Stack disclosure in hidden services logs when SafeLogging disabled

2017-09-18 Thread Nick Mathewson
[TROVE-2017-008. CVE-2017-0380. Severity: medium] Hello! We have found a possible problem with the code that reports an error during the construction of an introduction point circuit. Because of this bug, it is possible that some hidden services will sometimes write sensitive informatio