Update for Tor 0.3.5.11, 0.4.2.8, and 0.4.3.6 addressing DoS vulnerability.

New releases Corrective releases of the Tor toolkit (0.3.5.11, 0.4.2.8, 0.4.3.6, and 4.4.2-alpha) used to organize the work of the anonymous Tor network. The new versions address vulnerability (CVE-2020-15572), which was triggered by accessing memory outside the bounds of the allocated buffer. This vulnerability allows a remote attacker to initiate a crash of the tor process. The issue only occurs when compiled with the NSS library (by default, Tor is compiled with OpenSSL, and using NSS requires specifying the "--enable-nss" flag).

Additional introduced the plan to discontinue support for the second version of the onion services protocol (previously referred to as hidden services). One and a half years ago, in release 0.3.2.9, users were proposed introduced to the third version of the protocol for onion services, notable for its transition to 56-character addresses, more reliable protection against data leaks via directory servers, an expandable modular structure, and the use of SHA3, ed25519, and curve25519 algorithms instead of SHA1, DH, and RSA-1024.

The second version of the protocol was developed about 15 years ago and, due to the use of outdated algorithms, cannot be considered secure in modern conditions. Considering that support for old branches is ending, any current Tor gateway now supports the third version of the protocol, which is offered by default when creating new onion services.

On September 15, 2020, Tor will begin notifying operators and clients about the deprecation of the second version of the protocol. On July 15, 2021, support for the second version of the protocol will be removed from the codebase, and on October 15, 2021, a new stable release of Tor will be launched without support for the old protocol. Thus, owners of old onion services have 16 months to transition to the new version of the protocol, which requires generating a new 56-character address for the service.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster