Comment 4 for bug 1187001

Revision history for this message
Seth Arnold (seth-arnold) wrote :

I think this hasn't been addressed in part because it didn't get a CVE number: http://openwall.com/lists/oss-security/2013/07/12/4

Since the service appears to be restarting without qualm, I can see why it didn't get a CVE, but this does seem less than awesome.

Mancha made a lot of patches for services when the crypt() change happened, here's an email from him with upstream patch and two backported patches: http://openwall.com/lists/oss-security/2013/07/12/3