Bug#894438: libcrypt-u2f-server-perl: Crypt::U2F::Server fails when public key contains \0

Xavier Guimard x.guimard at free.fr
Fri Mar 30 10:15:43 UTC 2018


Package: libcrypt-u2f-server-perl
Version: 0.40-1
Severity: important
Tags: upstream, fixed-upstream
Forwarded: https://rt.cpan.org/Ticket/Display.html?id=114597https://rt.cpan.org/Ticket/Display.html?id=114597

A public key can have a null char in it. In that case, registration will
fail. This is due to a bad type mapping in XS file.

I've fixed this in next version (0.42)

-- System Information:
Debian Release: buster/sid
  APT prefers testing
  APT policy: (600, 'testing'), (50, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.14.0-3-amd64 (SMP w/2 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8), LANGUAGE= (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages libcrypt-u2f-server-perl depends on:
ii  libc6                       2.27-2
ii  libjson-xs-perl             3.040-1
ii  libu2f-server0              1.1.0-1
ii  perl                        5.26.1-5
ii  perl-base [perlapi-5.26.0]  5.26.1-5

libcrypt-u2f-server-perl recommends no packages.

libcrypt-u2f-server-perl suggests no packages.

-- no debconf information



More information about the pkg-perl-maintainers mailing list