Tor 0.2.4.26/0.2.5.11 发布,这两个版本上周就已经发布了,但是现在才发布发行说明。 Tor 0.2.4 和 0.2.5 是稳定版本系列,源代码现已提供下载:https://dist.torproject.org/。如果你运行 TorBrowser 4.0.5,那么就是使用 Tor 0.2.5.11。 这两个版本主要是 bug 修复,还有一些安全更新和节点更新。 0.2.4.26 - 2015-03-17 Directory authority changes: Remove turtles as a directory authority. Add longclaw as a new (v3) directory authority. This implements ticket 13296. This keeps the directory authority count at 9. The directory authority Faravahar has a new IP address. This closes ticket 14487. Major bugfixes (exit node stability, also in 0.2.6.3-alpha): Fix an assertion failure that could occur under high DNS load. Fixes bug 14129; bugfix on Tor 0.0.7rc1. Found by "jowr"; diagnosed and fixed by "cypherpunks". Major bugfixes (relay, stability, possible security, also in 0.2.6.4-rc): Fix a bug that could lead to a relay crashing with an assertion failure if a buffer of exactly the wrong layout was passed to buf_pullup() at exactly the wrong time. Fixes bug 15083; bugfix on 0.2.0.10-alpha. Patch from 'cypherpunks'. Do not assert if the 'data' pointer on a buffer is advanced to the very end of the buffer; log a BUG message instead. Only assert if it is past that point. Fixes bug 15083; bugfix on 0.2.0.10-alpha. Minor features (geoip): Update geoip to the March 3 2015 Maxmind GeoLite2 Country database. Update geoip6 to the March 3 2015 Maxmind GeoLite2 Country database. 0.2.5.11 - 2015-03-17 Directory authority changes: Remove turtles as a directory authority. Add longclaw as a new (v3) directory authority. This implements ticket 13296. This keeps the directory authority count at 9. The directory authority Faravahar has a new IP address. This closes ticket 14487. Major bugfixes (crash, OSX, security): Fix a remote denial-of-service opportunity caused by a bug in OSX's _strlcat_chk() function. Fixes bug 15205; bug first appeared in OSX 10.9. Major bugfixes (relay, stability, possible security): Fix a bug that could lead to a relay crashing with an assertion failure if a buffer of exactly the wrong layout was passed to buf_pullup() at exactly the wrong time. Fixes bug 15083; bugfix on 0.2.0.10-alpha. Patch from 'cypherpunks'. Do not assert if the 'data' pointer on a buffer is advanced to the very end of the buffer; log a BUG message instead. Only assert if it is past that point. Fixes bug 15083; bugfix on 0.2.0.10-alpha. Major bugfixes (exit node stability): Fix an assertion failure that could occur under high DNS load. Fixes bug 14129; bugfix on Tor 0.0.7rc1. Found by "jowr"; diagnosed and fixed by "cypherpunks". Major bugfixes (Linux seccomp2 sandbox): Upon receiving sighup with the seccomp2 sandbox enabled, do not crash during attempts to call wait4. Fixes bug 15088; bugfix on 0.2.5.1-alpha. Patch from "sanic". Minor features (controller): New "GETINFO bw-event-cache" to get information about recent bandwidth events. Closes ticket 14128. Useful for controllers to get recent bandwidth history after the fix for ticket 13988. Minor features (geoip): Update geoip to the March 3 2015 Maxmind GeoLite2 Country database. Update geoip6 to the March 3 2015 Maxmind GeoLite2 Country database. Minor bugfixes (client, automapping): Avoid crashing on torrc lines for VirtualAddrNetworkIPv[4|6] when no value follows the option. Fixes bug 14142; bugfix on 0.2.4.7-alpha. Patch by "teor". Fix a memory leak when using AutomapHostsOnResolve. Fixes bug 14195; bugfix on 0.1.0.1-rc. Minor bugfixes (compilation): Build without warnings with the stock OpenSSL srtp.h header, which has a duplicate declaration of SSL_get_selected_srtp_profile(). Fixes bug 14220; this is OpenSSL's bug, not ours. Minor bugfixes (directory authority): Allow directory authorities to fetch more data from one another if they find themselves missing lots of votes. Previously, they had been bumping against the 10 MB queued data limit. Fixes bug 14261; bugfix on 0.1.2.5-alpha. Enlarge the buffer to read bwauth generated files to avoid an issue when parsing the file in dirserv_read_measured_bandwidths(). Fixes bug 14125; bugfix on 0.2.2.1-alpha. Minor bugfixes (statistics): Increase period over which bandwidth observations are aggregated from 15 minutes to 4 hours. Fixes bug 13988; bugfix on 0.0.8pre1. Minor bugfixes (preventative security, C safety): When reading a hexadecimal, base-32, or base-64 encoded value from a string, always overwrite the whole output buffer. This prevents some bugs where we would look at (but fortunately, not reveal) uninitialized memory on the stack. Fixes bug 14013; bugfix on all versions of Tor. 更多内容请看发行说明。 Tor 是一个帮助你抵御流量分析的软件项目, 流量分析是一种对网络的监视行为。Tor 将你的通信通过一个由遍及全球的志愿者运行的中继(relay)所组成的分布式网络转发, 以此来保护你的安全:它令监视你的 Internet 连接的那些人无法知道你所访问的站点, 它还令你所访问的站点无法知道你的物理位置。Tor 能与现有的许多应用程序配合工作, 包括 Web 浏览器、即时通讯客户端、远程登录和基于 TCP 协议的其他应用程序。 Tor 0.2.4.26/0.2.5.11 发布,网络反监控系统下载地址