[Bug 1065429] [NEW] Long passwords for authenticated repositories not handled well

Michael Vogt michael.vogt at ubuntu.com
Thu Oct 11 09:15:46 UTC 2012


Public bug reported:

If there is a repository that needs authentication with a long password
(>64 chars) this is not handled well in apt. It will simply cut it off
and the authentication will fail with a error from the server instead of
indicating that the password is too long.

The maximum size of the user/password needs to be increased and a proper
error message on overflow needs to be given.

To test this we need a repository with a long username/password.

** Affects: apt (Ubuntu)
     Importance: Medium
         Status: Fix Released

** Affects: apt (Ubuntu Precise)
     Importance: Medium
         Status: In Progress

** Also affects: apt (Ubuntu Precise)
   Importance: Undecided
       Status: New

** Changed in: apt (Ubuntu)
       Status: New => Fix Released

** Changed in: apt (Ubuntu)
   Importance: Undecided => Medium

** Changed in: apt (Ubuntu Precise)
       Status: New => In Progress

** Changed in: apt (Ubuntu Precise)
   Importance: Undecided => Medium

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to apt in Ubuntu.
https://bugs.launchpad.net/bugs/1065429

Title:
  Long passwords for authenticated repositories not handled well

Status in “apt” package in Ubuntu:
  Fix Released
Status in “apt” source package in Precise:
  In Progress

Bug description:
  If there is a repository that needs authentication with a long
  password (>64 chars) this is not handled well in apt. It will simply
  cut it off and the authentication will fail with a error from the
  server instead of indicating that the password is too long.

  The maximum size of the user/password needs to be increased and a
  proper error message on overflow needs to be given.

  To test this we need a repository with a long username/password.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1065429/+subscriptions




More information about the foundations-bugs mailing list