Package: pwgen
Version: 2.05-1
Followup-For: Bug #368010

could you please upload the fix and the sevirity is grave in my opinion:
i tried to automatically create passwords in a script, and so there can
be severe security problem if i hadnt checked the output by hand since it
created both empty and numerous one char paswords that are not secure at
all.

my call was:
pwgen -cnsB 12 1

which results to for example
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
4smE 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
J 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
d 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
ot7yagRYkTxq 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1

[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
oR 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
pnrRNJyowF 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
XMyU 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
3Un7 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
v9EeNHfRv3LP 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
Jc9H9a 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
upfchLEWkCc4 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
eU3qE 
[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1

[EMAIL PROTECTED]:~]> pwgen -cnsB 12 1
3u3NfAe 

when called directly in the shell

yours
albert

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.21.1 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages pwgen depends on:
ii  libc6                         2.5-11     GNU C Library: Shared libraries

pwgen recommends no packages.

-- no debconf information


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to