[Tails-dev] [Tails News] Tails 5.19.1

Delete this message

Reply to this message
Author: Tails - News
Date:  
To: amnesia-news
Subject: [Tails-dev] [Tails News] Tails 5.19.1
# [Tails 5.19.1](https://tails.boum.org/news/version_5.19.1/index.en.html)

This release is an emergency release to fix an important security
vulnerability in Tor.

# Changes and updates

* Update the _Tor_ client to 0.4.8.9, which fixes the TROVE-2023-006 vulnerability.

The details of TROVE-2023-006 haven't been disclosed by the Tor Project to
leave time for users to upgrade before revealing more. We only know that the
Tor Project describes TROVE-2023-006 as a "[ _remote triggerable assert on
onion
services_](https://gitlab.torproject.org/tpo/core/team/-/wikis/NetworkTeam/TROVE)".

Our team thinks that this vulnerability could affect Tails users who are
creating onion services from their Tails, for example when sharing files or
publishing a website using _OnionShare_.

This vulnerability might allow an attacker who already knows your _OnionShare_
address to make your Tor client crash. A powerful attacker might be able to
further exploit this crash to reveal your IP address.

This analysis is only a hypothesis because our team doesn't have access to
more details about this vulnerability. Still, we are releasing this emergency
release as a precaution.

_OnionShare_ is the only application included in Tails that creates onion
services. You are not affected by this vulnerability if you don't use
_OnionShare_ in Tails and only use Tails to connect to onion services and
don't create onion services using Additional Software.

More details about TROVE-2023-006 will be available on the [Tor issue
#40883](https://gitlab.torproject.org/tpo/core/tor/-/issues/40883) sometime
after the release.

# Fixed problems

For more details, read our
[changelog](https://gitlab.tails.boum.org/tails/tails/-/blob/master/debian/changelog).

# Known issues

None specific to this release.

See the list of [long-standing
issues](https://tails.boum.org/support/known_issues/index.en.html).

# Get Tails 5.19.1

## To upgrade your Tails USB stick and keep your Persistent Storage

* Automatic upgrades are available from Tails 5.0 or later to 5.19.1.

You can [reduce the size of the
download](https://tails.boum.org/doc/upgrade/index.en.html#reduce) of future
automatic upgrades by doing a manual upgrade to the latest version.

* If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a [manual upgrade](https://tails.boum.org/doc/upgrade/index.en.html#manual).

## To install Tails on a new USB stick

Follow our installation instructions:

* [Install from Windows](https://tails.boum.org/install/windows/index.en.html)
* [Install from macOS](https://tails.boum.org/install/mac/index.en.html)
* [Install from Linux](https://tails.boum.org/install/linux/index.en.html)
* [Install from Debian or Ubuntu using the command line and GnuPG](https://tails.boum.org/install/expert/index.en.html)

The Persistent Storage on the USB stick will be lost if you install instead of
upgrading.

## To download only

If you don't need installation or upgrade instructions, you can download Tails
5.19.1 directly:

* [For USB sticks (USB image)](https://tails.boum.org/install/download/index.en.html)
* [For DVDs and virtual machines (ISO image)](https://tails.boum.org/install/download-iso/index.en.html)

URL: <https://tails.boum.org/news/version_5.19.1/index.en.html>

--
Tails News
https://www.autistici.org/mailman/listinfo/amnesia-news
To unsubscribe, send an empty email to amnesia-news-unsubscribe@???.