Stable release 0.4.7.8

Where to Download

Verifying Tarballs

Please read our guide here

Changes

Below are the major changes of the released versions and links to more detailed release notes.

Stable

Today, we release 0.4.7.8 fixing several issues including a High severity security issue only affecting the 0.4.7.x series. You can track this issue with TROVE-2022-001 and CVE-2021-38385.

Please note that at the moment, the full details of the security issue are not yet public as we are waiting on the OS distribution packages to be updated and the network to be on its upgrade path.

This security issue is not affecting the safety of the tor host system itself and is categorized as a Denial of Service thus affecting performance and possibly anonymity.

We STRONGLY recommend anyone on an earlier version to upgrade as soon as possible to tor 0.4.7.8 (this release). OS packages are on the way!

Release Notes

5 Likes

Looks like there is a typo in the CVE identifier in this post. The correct CVE identifier is CVE-2022-33903 which is also used in the release notes.

Thanks to omni for letting us know!

3 Likes