Yes, when I reported this bug I sent the patch to the developer and he added it. Thanks Jari.
On Thu, Jan 7, 2010 at 2:30 AM, Debian Bug Tracking System <ow...@bugs.debian.org> wrote: > This is an automatic notification regarding your Bug report > which was filed against the fcrackzip package: > > #500750: [fcrackzip] Segmentation Fault when init-password string is longer > than MAX_PW (40) > > It has been closed by Jari Aalto <jari.aa...@cante.net>. > > Their explanation is attached below along with your original report. > If this explanation is unsatisfactory and you have not received a > better one in a separate message then please contact Jari Aalto > <jari.aa...@cante.net> by > replying to this email. > > > -- > 500750: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=500750 > Debian Bug Tracking System > Contact ow...@bugs.debian.org with problems > > > ---------- Forwarded message ---------- > From: Jari Aalto <jari.aa...@cante.net> > To: 500750-cl...@bugs.debian.org > Date: Thu, 07 Jan 2010 05:17:07 +0000 > Subject: Bug#500750: fixed in fcrackzip 1.0-1 > Source: fcrackzip > Source-Version: 1.0-1 > > We believe that the bug you reported is fixed in the latest version of > fcrackzip, which is due to be installed in the Debian FTP archive: > > fcrackzip_1.0-1.debian.tar.gz > to main/f/fcrackzip/fcrackzip_1.0-1.debian.tar.gz > fcrackzip_1.0-1.dsc > to main/f/fcrackzip/fcrackzip_1.0-1.dsc > fcrackzip_1.0-1_i386.deb > to main/f/fcrackzip/fcrackzip_1.0-1_i386.deb > fcrackzip_1.0.orig.tar.gz > to main/f/fcrackzip/fcrackzip_1.0.orig.tar.gz > > > > A summary of the changes between this version and the previous one is > attached. > > Thank you for reporting the bug, which will now be closed. If you > have further comments please address them to 500...@bugs.debian.org, > and the maintainer will reopen the bug report if appropriate. > > Debian distribution maintenance software > pp. > Jari Aalto <jari.aa...@cante.net> (supplier of updated fcrackzip package) > > (This message was generated automatically at their request; if you > believe that there is a problem with it please contact the archive > administrators by mailing ftpmas...@debian.org) > > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Format: 1.8 > Date: Tue, 05 Jan 2010 20:28:03 +0200 > Source: fcrackzip > Binary: fcrackzip > Architecture: source i386 > Version: 1.0-1 > Distribution: unstable > Urgency: low > Maintainer: Jari Aalto <jari.aa...@cante.net> > Changed-By: Jari Aalto <jari.aa...@cante.net> > Description: > fcrackzip - password cracker for zip archives > Closes: 430387 500750 528219 531657 555125 > Changes: > fcrackzip (1.0-1) unstable; urgency=low > . > * New maintainer (ITA; Closes: #555125) > - New version (Closes: #531657). > - Pw is not initialized and read from stdin (Closes: #528219). > - Segmentation Fault when init-password string is > longer than MAX_PW (40)(Closes: #500750). > - Move to format: 3.0 (quilt). > * debian/clean > - New file. > * debian/compat > - Update to 7. > * debian/control > - (Build-Depends): update to debhelper 7, remove old version > from autotools-dev. > - (Homepage): New field. > - (Standards-Version): update to 3.8.3. > * debian/copyright > - Update layout. > * debian/debian-{autotools,compile,vars}.mk > - New files. > * debian/fcrackzipinfo.1 > - Delete, convert to POD format. > * debian/fcrackzipinfo.1.pod > - New file. > * debian/fcrackzip.{examples,manpages} > - Move content from rules for dh(1). > * debian/patches > - (10): New; fix hyphens in manual page. > - (20): New; handle special files (Closes: #430387). > * debian/pod2man.mk > - New file. > * debian/rules > - Update to dh(1). > * debian/watch > - New file. > Checksums-Sha1: > 6a4a0e8dc6c2a2d698854281a360b96408d17f70 1163 fcrackzip_1.0-1.dsc > 92e4f8caa880c55b20e13feb7a25c8b8fd3accf8 114786 fcrackzip_1.0.orig.tar.gz > 25ae94f0f4830bcee1310a18b1e7e01ba580cd17 9892 fcrackzip_1.0-1.debian.tar.gz > 6c01628792eabb424e2c1cf359b656e21b85987f 26756 fcrackzip_1.0-1_i386.deb > Checksums-Sha256: > fb1013641d44bca1e4c9efeb8ed4adc6ce939677c8d118d83695029cf1ea1f17 1163 > fcrackzip_1.0-1.dsc > 4a58c8cb98177514ba17ee30d28d4927918bf0bdc3c94d260adfee44d2d43850 114786 > fcrackzip_1.0.orig.tar.gz > fc1bf7d98b151b4842a8a65b2a6e2dc53c0cd941556cbc5decbb7e4f0d6711d4 9892 > fcrackzip_1.0-1.debian.tar.gz > 1738839f8aa05c7564b0d82e0cce100f4e81261848e430766dfca29d6e2f958e 26756 > fcrackzip_1.0-1_i386.deb > Files: > d5eee9449f423b954298ccc720da4e49 1163 utils optional fcrackzip_1.0-1.dsc > 254941f51759f9425965f4b05fe7ac2c 114786 utils optional > fcrackzip_1.0.orig.tar.gz > 1a9c0c5bf5f9774b785a288861b4e750 9892 utils optional > fcrackzip_1.0-1.debian.tar.gz > c2aad40f45d9fc78185845309663a9cf 26756 utils optional > fcrackzip_1.0-1_i386.deb > > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.10 (GNU/Linux) > > iEYEARECAAYFAktFaz0ACgkQpdwBkPlyvgMN0ACfUh8rOndhWw1vfoWkf2R8T54N > qysAniuJWfFpBzzxE+EphtxqqMwZk2iK > =sSzg > -----END PGP SIGNATURE----- > > > > > ---------- Forwarded message ---------- > From: Macarse <maca...@gmail.com> > To: sub...@bugs.debian.org > Date: Wed, 01 Oct 2008 00:58:02 -0300 > Subject: [fcrackzip] Segmentation Fault when init-password string is longer > than MAX_PW (40) > Package: fcrackzip > Version: 0.3-2 > Severity: normal > > --- Please enter the report below this line. --- > Calls like this: fcrackzip -c 1 -p > 11111111111111111111111111111111111111111111111 a.zip causes Segmentation > Faults. > > Patch: > $ diff main.old.c main.c > 377a378,382 >> if (strlen(optarg) > MAX_PW) >> { >> fprintf (stderr, "'%s' is too long. Max lenght = %d\n", optarg, >> MAX_PW); >> exit (1); >> } > > --- System information. --- > Architecture: i386 > Kernel: Linux 2.6.26-1-686 > > Debian Release: lenny/sid > 500 testing www.debian-multimedia.org > 500 testing security.debian.org > 500 testing http.us.debian.org > > --- Package information. --- > Depends (Version) | Installed > =============================-+-================= > libc6 (>= 2.3.2.ds1-4) | 2.7-13 > > > > > -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org