Package: cracklib-runtime
Version: 2.8.19-3
Severity: normal

Dear Maintainer,

To reproduce for utf8 based word lists:

  $ sudo aptitude install wspanish wamerican

This one is rightly denied:

  $ sudo cracklib-check # By the way, why is root access necessary?
  blithely
  blithely: it is based on a dictionary word
  blithely3
  blithely3: it is based on a dictionary word

but aarónica3 should also be denied:

  aarónica
  aarónica: it is based on a dictionary word
  aarónica3
  aarónica3: OK

just as this one is:

  aarónica=
  aarónica=: it is based on a dictionary word

In addition too short passwords are accepted:

  årchk
  årchk: OK
  archk
  archk: it is too short
  åòÉü
  åòÉü: OK

These possibly constitute a security risk since such bad passwords are
popular...


Best regards,
Tore



-- System Information:
Debian Release: 7.1
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.2.0-4-amd64 (SMP w/4 CPU cores)
Locale: LANG=nb_NO.utf8, LC_CTYPE=nb_NO.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages cracklib-runtime depends on:
ii  file       5.11-2
ii  libc6      2.13-38
ii  libcrack2  2.8.19-3
ii  zlib1g     1:1.2.7.dfsg-13

Versions of packages cracklib-runtime recommends:
ii  wamerican [wordlist]   7.1-1
ii  wnorwegian [wordlist]  2.0.10-5.1
ii  wspanish [wordlist]    1.0.26
ii  wswedish [wordlist]    1.4.5-2.1

cracklib-runtime suggests no packages.

-- Configuration Files:
/etc/logcheck/ignore.d.paranoid/cracklib-runtime [Errno 13] Ikke tilgang: 
u'/etc/logcheck/ignore.d.paranoid/cracklib-runtime'

-- debconf-show failed


--
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to