[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: license incompatibility of cowpatty + openssl



Hello Joshua,

I just updated the patch against cowpatty's master and filled a PR

https://github.com/joswr1ght/cowpatty/pull/4

Thanks

On Wed, 4 Jul 2018 at 19:51, Samuel Henrique <samueloph@debian.org> wrote:
Hello once again,

Thanks for accepting the PR's and trigerring a new release.

I believe there's just one thing more, there's a patch being applied on kali's cowpatty which i bet you'd like to add to cowpatty. I talked about that on the #2 PR (https://github.com/joswr1ght/cowpatty/pull/2#issuecomment-402283071).

But the patch seems to be fixing a buffer overflow, I believe it was made by Mati Aharoni <muts@kali.org> and i found references of the patch in various places online.

https://www.question-defense.com/2009/12/24/cowpatty-buffer-overflow

You can see here that Arch is also applying the patch (https://git.archlinux.org/svntogit/community.git/tree/trunk?h=packages/cowpatty).

What do you think?

And once again, thanks for responsiveness.


On Sun, 1 Jul 2018 at 18:28, Samuel Henrique <samueloph@debian.org> wrote:
Hello Joshua,

I just sent the second PR which adds a simple manpage for cowpatty and genpmk based on their help output.

As i mentioned on the PRs[0][1], it would be very helpful if you could do a new release after merging both of them. It would be more noticeable if there was a new release since you changed cowpatty's license,

Thanks a lot for your responsiveness regarding all of this.

PS.: I'm not sure if i should be sending this to the two emails of yours that i found (if not, please say so). And also i'm CCing debian security tools list, which is public.

--
Samuel Henrique <samueloph>


--
Samuel Henrique <samueloph>


--
Samuel Henrique <samueloph>

Reply to: