Accepted tor (source all amd64)

Format: 1.8
Date: Thu, 12 Jul 2012 20:56:56 UTC
Source: tor
Binary: tor tor-dbg tor-geoipdb
Architecture: source all amd64
Distribution: stable
Urgency: medium
Maintainer: Peter Palfrader <weasel@debian.org>
Changed-By: Peter Palfrader <weasel@debian.org>
 tor        - anonymizing overlay network for TCP
 tor-dbg    - debugging symbols for Tor
 tor-geoipdb - geoIP database for Tor
 tor ( stable; urgency=low
   * Update tor in stable to as per discussion in #679224:
     - This version fixes a couple of minor security issues, like no longer
       leaking uninitialized memory, properly rejecting inputs where the number
       exceeds valid values for its storage types, or not adding more bytes to
       input buffers while renegotiating.
     - Furthermore, a few issues are resolved that might affect a user's
       anonymity.  These include things such as only building circuits when a
       client knows a sufficient number of "exit" nodes, never using a bridge
       as an exit, or reusing circuits in an unsafe manner.
     - Additionaly it updates the list of directory authorities, makes building
       with newer and older openssl libraries safer (probably not important for
       us) and makes building on a few other platforms more robust.
     - For details please consult the upstream changelog entries.
 tor ( unstable; urgency=medium
   * New upstream version, including:
     - Work around a bug in OpenSSL that broke renegotiation with TLS
       1.1 and TLS 1.2. Without this workaround, all attempts to speak
       the v2 Tor connection protocol when both sides were using OpenSSL
       1.0.1 would fail. Resolves ticket 6033.
     - When waiting for a client to renegotiate, don't allow it to add
       any bytes to the input buffer. This fixes a potential DoS issue.
       Fixes bugs 5934 and 6007; bugfix on
     - and more.  See upstream's changelog.
 tor ( unstable; urgency=low
   * New upstream version, including updates to authority addresses, and
     a couple minor security issues, see upstream's changelog.
