issue-2011-10-19L 577 B

123456789101112
  1. o Security fixes:
  2. - Don't send TLS certificate chains on outgoing OR connections
  3. from clients and bridges. Previously, each client or bridge
  4. would use a single cert chain for all outgoing OR connections
  5. for up to 24 hours, which allowed any relay connected to by a
  6. client or bridge to determine which entry guards it is using.
  7. This is a potential user-tracing bug for *all* users; everyone
  8. who uses Tor's client or hidden service functionality should
  9. upgrade. Fixes CVE-2011-2768. Bugfix on FIXME; found by
  10. frosty_un.