oss-sec mailing list archives

Re: CVE request: crypt_blowfish 8-bit character mishandling


From: Solar Designer <solar () openwall com>
Date: Tue, 21 Jun 2011 21:55:26 +0400

On Tue, Jun 21, 2011 at 10:50:18AM -0600, Vincent Danen wrote:
So Crypt::Eksblowfish uses the same code but wasn't affected?  Do we
know why that is?

It is based on the same code, but the author made changes when merging
the code.  Specifically, he switched to using "unsigned char *".

I can't promise I will have time to look at it, but I will try if I can
find the time.

Thanks!

Meanwhile, I've released crypt_blowfish 1.1 with the fixes I had
mentioned in here.

http://www.openwall.com/crypt/

Alexander


Current thread: