Bug#726578: Ping: pwgen: Multiple vulnerabilities in passwords generation

2014-01-14 Thread Arne Wichmann
Thank you for reacting quickly! begin quotation from Theodore Ts'o (in <20140112234500.ga15...@thunk.org>): > On Sun, Jan 12, 2014 at 09:27:14PM +0100, Arne Wichmann wrote: > > This grave problem is now open for more than two months. Is there any plan > > to resolve this? > > First, the CVE abo

Bug#726578: Ping: pwgen: Multiple vulnerabilities in passwords generation

2014-01-12 Thread Theodore Ts'o
On Sun, Jan 12, 2014 at 09:27:14PM +0100, Arne Wichmann wrote: > > This grave problem is now open for more than two months. Is there any plan > to resolve this? First, the CVE about having the unavailability of /dev/random fail hard -- sure, that should be a separate bug since that's a fix that I

Bug#726578: Ping: pwgen: Multiple vulnerabilities in passwords generation

2014-01-12 Thread Arne Wichmann
Hi! This grave problem is now open for more than two months. Is there any plan to resolve this? cu AW -- [...] If you don't want to be restricted, don't agree to it. If you are coerced, comply as much as you must to protect yourself, just don't support it. Noone can free you but yourself. (crag