Re: pycrypto buffer overflow (potentially affects onionshare and other packages)

2017-01-09 Thread Leo Famulari
On Thu, Jan 05, 2017 at 11:39:58AM +0100, Ludovic Courtès wrote: > Leo Famulari skribis: > > > On Mon, Jan 02, 2017 at 09:41:26PM +0100, Ludovic Courtès wrote: > >> Leo Famulari skribis: > >> > Based on my discussion with the Stem maintainer, I removed

Re: pycrypto buffer overflow (potentially affects onionshare and other packages)

2017-01-05 Thread Ludovic Courtès
Leo Famulari skribis: > On Mon, Jan 02, 2017 at 09:41:26PM +0100, Ludovic Courtès wrote: >> Leo Famulari skribis: >> > Based on my discussion with the Stem maintainer, I removed pycrypto from >> > the dependency graph of OnionShare and added a comment

Re: pycrypto buffer overflow (potentially affects onionshare and other packages)

2017-01-02 Thread Leo Famulari
On Mon, Jan 02, 2017 at 09:41:26PM +0100, Ludovic Courtès wrote: > Leo Famulari skribis: > > Based on my discussion with the Stem maintainer, I removed pycrypto from > > the dependency graph of OnionShare and added a comment about removing > > the pycrypto package in

Re: pycrypto buffer overflow (potentially affects onionshare and other packages)

2017-01-02 Thread Ludovic Courtès
Leo Famulari skribis: > On Mon, Dec 26, 2016 at 01:08:44PM -0500, Leo Famulari wrote: >> On Mon, Dec 26, 2016 at 12:43:44PM -0500, Leo Famulari wrote: >> > The list of our packages that use pycrypto: >> >> [...] >> >> > onionshare-0.9.2 >> >> This comes through

Re: pycrypto buffer overflow (potentially affects onionshare and other packages)

2016-12-26 Thread Leo Famulari
On Mon, Dec 26, 2016 at 01:08:44PM -0500, Leo Famulari wrote: > On Mon, Dec 26, 2016 at 12:43:44PM -0500, Leo Famulari wrote: > > The list of our packages that use pycrypto: > > [...] > > > onionshare-0.9.2 > > This comes through python-stem. I've contacted the stem maintainer about > this

Re: pycrypto buffer overflow (potentially affects onionshare and other packages)

2016-12-26 Thread Leo Famulari
On Mon, Dec 26, 2016 at 12:43:44PM -0500, Leo Famulari wrote: > The list of our packages that use pycrypto: [...] > onionshare-0.9.2 This comes through python-stem. I've contacted the stem maintainer about this issue. signature.asc Description: PGP signature

pycrypto buffer overflow (potentially affects onionshare and other packages)

2016-12-26 Thread Leo Famulari
The pycrypto library contains at least one dangerous buffer overflow: https://github.com/dlitz/pycrypto/issues/176 And the pycrypto project is inactive: https://github.com/dlitz/pycrypto/issues/173 The list of our packages that use pycrypto: python-axolotl-0.1.35 onionshare-0.9.2