Tor updates 0.3.5.10, 0.4.1.9, and 0.4.2.7 with DoS vulnerability fixes

New releases Corrective releases of the Tor toolkit (0.3.5.10, 0.4.1.9, 0.4.2.7, 0.4.3.3-alpha) used to facilitate the operation of the anonymous Tor network. The new versions fix two vulnerabilities:

  • CVE-2020-10592 — can be used by any attacker to initiate a denial of service against relays. The attack can also be conducted from Tor directory servers to target clients and hidden services. An attacker can create conditions that lead to excessive CPU load, disrupting normal operation for several seconds or minutes (repeating the attack can extend the DoS for a longer duration). The issue has been present since release 0.2.1.5-alpha.
  • CVE-2020-10593 — a remotely triggered memory leak occurring during dual negotiation of circuit padding for the same circuit.

It can also be noted that in Tor Browser 9.0.6 a vulnerability in the extension NoScript, allows the execution of JavaScript code in "Safest" protection mode. For those who find a ban on JavaScript execution important, it is recommended to completely prohibit the use of JavaScript in the browser temporarily through the setting javascript.enabled in about:config.

An attempt to fix this shortcoming was made in NoScript 11.0.17, but it turned out that the proposed fix does not completely resolve the issue. According to the changes in the subsequently released version NoScript 11.0.18, the problem remains unresolved as well. Tor Browser includes automatic updates for NoScript, so once a fix is available, it will be delivered automatically.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster