K 10 svn:author V 3 des K 8 svn:date V 27 2017-10-26T13:23:13.087772Z K 7 svn:log V 242 If the user-provided password exceeds the maximum password length, don't bother passing it to crypt(). It won't succeed and may allow an attacker to confirm that the user exists. Reported by: jkim@ MFC after: 1 week Security: CVE-2016-6210 END