Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 11 Sep 2015 08:42:37 -0500
From: JimF <jfoug@....net>
To: john-dev@...ts.openwall.com
Subject: Re: auditing our use of FMT_* flags

There was a split() in the jumbo version where the return of split was 
strlwr()   At least that was there by the time I got my searching 
function completed.

On 9/11/2015 4:38 AM, Solar Designer wrote:
>
> issing.  My method actually 'tests' the bug.
> I disagree that everything in AFS except the flag was correct.  AFS uses
> hex-encoded strings.  Until my fix yesterday, AFS accepted arbitrary and
> mixed-case hex encodings.  It uses fmt_default_split().
>
> I think your test, as you describe it, should have caught the AFS bug.
> That it did not tells me that there's probably a bug in your test that
> you'd want to identify.

Powered by blists - more mailing lists

Your e-mail address:

Powered by Openwall GNU/*/Linux - Powered by OpenVZ