pkgsrc/security/oath-toolkit/distinfo
pettai 6bad46d81b Version 2.4.1 (released 2014-02-12)
* liboath: Fix usersfile bug that caused it to update the wrong line.
When an usersfile contain multiple lines for the same user but with an
unparseable token type (e.g., HOTP vs TOTP), the code would update the
wrong line of the file.  Since the then updated line could be a
commented out line, this can lead to the same OTP being accepted
multiple times which is a security vulnerability. CVE-2013-7322
CVs: ----------------------------------------------------------------------
2014-03-10 00:58:51 +00:00

7 lines
414 B
Text

$NetBSD: distinfo,v 1.10 2014/03/10 00:58:51 pettai Exp $
SHA1 (oath-toolkit-2.4.1.tar.gz) = b0ca4c5f89c12c550f7227123c2f21f45b2bf969
RMD160 (oath-toolkit-2.4.1.tar.gz) = d902ebef5b0468f383bcb15a9e8b0582011eb4ca
Size (oath-toolkit-2.4.1.tar.gz) = 4136649 bytes
SHA1 (patch-liboath_gl_fflush.c) = d957eed6c3e653ee53bbcf0b95b0c032f092b07d
SHA1 (patch-liboath_gl_fseeko.c) = bd67a1af8c01a2dbf849f8612cbb18470cb3b248