{"id":"MGASA-2017-0353","summary":"Updated tor packages fix security vulnerability","details":"Due to the code that reports an error during the construction of an\nintroduction point circuit, it is possible that some hidden services\nwill sometimes write sensitive information into their logs if the\nSafeLogging option is disabled.  Note that SafeLogging is enabled by\ndefault (CVE-2017-0380).\n","modified":"2026-04-16T06:25:52.288654043Z","published":"2017-09-21T13:43:32Z","upstream":["CVE-2017-0380"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2017-0353.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=21740"},{"type":"WEB","url":"https://lists.torproject.org/pipermail/tor-talk/2017-September/043585.html"},{"type":"WEB","url":"https://blog.torproject.org/new-tor-stable-releases-02815-02912-03011-fix-onion-service-security-issue"}],"affected":[{"package":{"name":"tor","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/tor?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.8.15-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0353.json"}},{"package":{"name":"tor","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/tor?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.9.12-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0353.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}