outdated Tor version in Fedora (missing security fixes)

Christoph A. casmls at gmail.com
Fri Jun 3 23:10:24 UTC 2011


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi Enrico,

I suppose you are the maintainer of the tor package in Fedora.
I'm wondering why Fedora (13,14,15) currently doesn't contain the latest
stable Tor version 0.2.1.30 which was released on 2011-02-23 and
contains various security fixes (since 0.2.1.28). [1]

The build was already done months ago:
http://koji.fedoraproject.org/koji/buildinfo?buildID=234269

Fedora currently contains 0.2.1.28 (from 2010-12-17).

Do you know the reason for this?

thanks,
Christoph

[1]
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-0427
https://bugzilla.redhat.com/show_bug.cgi?id=705192
-----BEGIN PGP SIGNATURE-----

iEYEAREKAAYFAk3paeAACgkQrq+riTAIEg2SigCgnsf1wPc3iDLzT7IbNS5l7NLD
xKsAnRou+X2oAWDh5axcDjt6TWjW0m2L
=hxYq
-----END PGP SIGNATURE-----


More information about the users mailing list