Freenet: Deanonymization Vulnerability — GLSA 202407-28

A vulnerability has been discovered in Freenet, which can lead to deanonymization due to path folding.

Affected packages

net-p2p/freenet on all architectures
Affected versions < 0.7.5_p1497
Unaffected versions >= 0.7.5_p1497

Background

Freenet is an encrypted network without censorship.

Description

This release fixes a severe vulnerability in path folding that allowed to distinguish between downloaders and forwarders with an adapted node that is directly connected via opennet.

Impact

This release fixes a severe vulnerability in path folding that allowed to distinguish between downloaders and forwarders with an adapted node that is directly connected via opennet.

Workaround

There is no known workaround at this time.

Resolution

All Freenet users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=net-p2p/freenet-0.7.5_p1497"
 

References

Release date
July 24, 2024

Latest revision
July 24, 2024: 1

Severity
normal

Exploitable
remote

Bugzilla entries