On Thu, 18 Jul 2013, Carlos O'Donell wrote:

> >   * CVE-2013-4122: Handle NULL returns from glibc 2.17+ crypt()
> >     (Closes: #716835)

> I'm happy to see applications being fixed to follow the 
> documented standard.

Which is a violation of historic practice and “common law”.

I’d be as happy to see the documented standard fixed.

Oh well. I uploaded a new cvs package to Debian sid
yesterday that handles NULL returns as well (review
of that diff is welcome, ofc), but IMHO the greater
issue remains.

bye,
//mirabilos
-- 
«MyISAM tables -will- get corrupted eventually. This is a fact of life. »
“mysql is about as much database as ms access” – “MSSQL at least descends
from a database” “it's a rebranded SyBase” “MySQL however was born from a
flatfile and went downhill from there” – “at least jetDB doesn’t claim to
be a database”  (#nosec)    ‣‣‣ Please let MySQL and MariaDB finally die!


--
To UNSUBSCRIBE, email to debian-glibc-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/alpine.deb.2.10.1307190921230.30...@tglase.lan.tarent.de

Reply via email to