• [gentoo-announce] [ GLSA 202407-28 ] Freenet: Deanonymization Vulnerabi

    From [email protected]@21:1/5 to All on Wed Jul 24 08:20:01 2024
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 202407-28
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    https://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
    Title: Freenet: Deanonymization Vulnerability
    Date: July 24, 2024
    Bugs: #904441
    ID: 202407-28

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    A vulnerability has been discovered in Freenet, which can lead to deanonymization due to path folding.

    Background
    ==========

    Freenet is an encrypted network without censorship.

    Affected packages
    =================

    Package Vulnerable Unaffected
    --------------- ------------- --------------
    net-p2p/freenet < 0.7.5_p1497 >= 0.7.5_p1497

    Description
    ===========

    This release fixes a severe vulnerability in path folding that allowed
    to distinguish between downloaders and forwarders with an adapted
    node that is directly connected via opennet.

    Impact
    ======

    This release fixes a severe vulnerability in path folding that allowed
    to distinguish between downloaders and forwarders with an adapted
    node that is directly connected via opennet.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All Freenet users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=net-p2p/freenet-0.7.5_p1497"

    References
    ==========


    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

    https://security.gentoo.org/glsa/202407-28

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to [email protected] or alternatively, you may file a bug at https://bugs.gentoo.org.

    License
    =======

    Copyright 2024 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    https://creativecommons.org/licenses/by-sa/2.5
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmagmugACgkQFMQkOaVy +9n/PhAAtNzX8mOEwfX2QJj08TkRrXe7PKUUuB68UVqia/fkV/IvRuhvcxSv8p4s KTk9gPqUxlVYzCgl04m4FpRFv/75uublLMnhUniNQH8zLmcamEE8C2XWMhTKHfW4 ZycVoNVlyXwOfWU8cKU0emTxraQcRuh2CI651EElDjtQdkvQbAm91StzmpXnyefV H6HZC/Ub8mPe3/cbHmbsLhC7c4bUvgdM6C++YxiT2y/HwLy3oOVKcHN3NxvXr0Q1 /XWbIFKCrhvH09sUPatONUjj2eYIIfbq2yaVoC2lFAycEKiT8Xsin7UbBSmfK4B4 X9cTj8NEzNit+9BjlSL0hAWR9ynCNojo2atBmi2QENzBLBQBWncFBIg+MxyrPn85 k1+XjZedG0QVr+K5473f9SO68+6j195g6/WCbseNjivSusvdcaW1285VtKvHbIjp ILxRFr1iXK2ONMg8cH3aYVKBedR4bN8eNTwzk4am/0HGXQMxUkf4DVXzRKnMXCDX 2QfCz7KFMJJRqJxNT1st+TsrrLqxKE3m+/W+kzXeBokoevu7qb6CQXWYEuqD7jWr nrQkfZNAALscON9tIwmA5mqL5aUNExh/D+7LHcHDB1EEm4tStOpMBFReswhh0mn3 PrGdyWUBgNvfxRJicpA+rg6sNiUmLH+qRqvMAnWa9u7IrD9oNOQ=
    =0g3S
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)