Bug#961429: RFS: cryptopass/1.0.0-1 [ITP] -- CLI utility for generating long, unguessable passwords.

2020-05-26 Thread Vasyl Gello
Hi Matthew! >This prompted me to take a quick look at the source. There are multiple >trivially exploitable buffer overflows in this code. E.g. >src/cryptopass.c:147-149 [0]: > >usernamelen = strlen(argv[1]); > >memcpy(username, argv[1], usernamelen); > >You could argue this program is o

Bug#961429: RFS: cryptopass/1.0.0-1 [ITP] -- CLI utility for generating long, unguessable passwords.

2020-05-26 Thread Matthew Fernandez
> On May 26, 2020, at 15:10, Mattia Rizzolo wrote: > > * building the package shows this "scary" GCC warning: > |In file included from /usr/include/string.h:495, > | from cryptopass.c:19: > |In function 'strncpy', > |inlined from 'main' at cryptopass.c:200:9: > |/usr/includ

Bug#961429: RFS: cryptopass/1.0.0-1 [ITP] -- CLI utility for generating long, unguessable passwords.

2020-05-26 Thread Mattia Rizzolo
Control: owner -1 ! Control: tag -1 moreinfo On Sun, May 24, 2020 at 02:22:42PM +, Vasyl Gello wrote: > I am looking for a sponsor for my package "cryptopass" o/ > * Vcs : https://salsa.debian.org/basilgello-guest/cryptopass I'm mostly looking at the VCS, but I'm not ignoring t

Bug#961628: RFS: shotwell/0.30.10-1 -- digital photo organizer

2020-05-26 Thread Jörg Frings-Fürst
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "shotwell" Package name: shotwell Version : 0.30.10-1 Upstream Author : Jim Nelson URL : https://wiki.gnome.org/Apps/Shotwell License : LGPL-2.1

Bug#960572: RFS: vim-ale/2.6.0-1 [ITP] (Asynchronous Lint Engine for Vim 8 and NeoVim), vim-vader/0.3.0+git20200213.6fff477-1 [ITP] (simple vimscript test framework)

2020-05-26 Thread Pierre-Elliott Bécue
Control: owner -1 james...@debian.org Le lundi 25 mai 2020 à 14:44:20+0200, Pierre-Elliott Bécue a écrit : > Dear Nicholas, > > Thanks for your work, I'll review it! > > A few preliminary remarks: > > on salsa's repo for vim-ale, you've created a debian/master branch that > is merely the same a