On Tue, Jun 07, 2011 at 02:09:26AM +0100, David-Sarah Hopwood wrote: > On 07/06/11 01:17, Paul Hummer wrote: > > Hi folks- > > > > The context of this email is here: > > > > https://code.launchpad.net/~jtaylor/ubuntu/oneiric/tahoe-lafs/tahoe-lafs-fix/+merge/63631 > > I don't see what the difficulty is in upgrading the Ubuntu pycryptopp > package to 0.5.20. That is the simplest way for Tahoe to be as sure as > it can be (against accidental misconfigurations) that it is getting a > pycryptopp that will use a Crypto++ that fixes these SHA-256 and AES bugs.
I reported on the python-pycryptopp Debian package that upstream released a new version [1]. Note that although it wasn't released yet, some work have been done on this package recently (well 02/12), if you have a look at its repo [2]. crypto++ package in Debian seems to be quite up to date too. [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=623411 [2] http://anonscm.debian.org/viewvc/python-modules/packages/pycryptopp/ _______________________________________________ tahoe-dev mailing list [email protected] http://tahoe-lafs.org/cgi-bin/mailman/listinfo/tahoe-dev
