{"thread":{"id":"49139","subject":"Re: Potential vulnerability: 'mixed up' output when commit has multiple signatures","startedAt":"2018-08-15T21:20:14Z","lastAt":"2018-08-15T21:20:35Z","messageCount":2,"participants":["Jonathan Nieder","Michał Górny"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"355766","messageId":"20180815212009.GE181377@aiede.svl.corp.google.com","threadId":"49139","inReplyTo":"1534315421.1603.0.camel@gentoo.org","subject":"Re: Potential vulnerability: 'mixed up' output when commit has multiple signatures","fromName":"Jonathan Nieder","fromEmail":"jrnieder@gmail.com","sentAt":"2018-08-15T21:20:09Z","receivedAt":"2018-08-15T21:20:14Z","isPatch":false,"sender":{"key":"jrnieder@gmail.com","avatar":"https://avatars.githubusercontent.com/u/281595?v=4"},"body":"Michał Górny wrote:\n> On Tue, 2018-08-14 at 22:35 -0700, Jonathan Nieder wrote:\n> > Michał Górny wrote:\n\n>>> I've been testing the git signature verification a bit and I've\n>>> discovered a troubling behavior when the commit object contains\n>>> multiple signatures.\n>>\n>> Thanks for discovering this.  Do you mind if I take this conversation\n>> to the public mailing list?  (I'd bounce the existing thread there if\n>> that's okay with you.)\n>\n> I've already asked somewhere else in the thread if you consider this\n> suitable for disclosure, and haven't received a reply yet.  In any case,\n> I don't mind it.\n\nThanks, doing so.\n\nThanks again for the analysis and fix as well.\n"},{"id":"355767","messageId":"1534315421.1603.0.camel@gentoo.org","threadId":"49139","inReplyTo":"20180815053522.GI32543@aiede.svl.corp.google.com","subject":"Re: Potential vulnerability: 'mixed up' output when commit has multiple signatures","fromName":"Michał Górny","fromEmail":"mgorny@gentoo.org","sentAt":"2018-08-15T06:43:41Z","receivedAt":"2018-08-15T21:20:35Z","isPatch":false,"sender":{"key":"mgorny@gentoo.org","avatar":"https://avatars.githubusercontent.com/u/110765?v=4"},"body":"On Tue, 2018-08-14 at 22:35 -0700, Jonathan Nieder wrote:\n> Hi,\n> \n> Michał Górny wrote:\n> \n> > I've been testing the git signature verification a bit and I've\n> > discovered a troubling behavior when the commit object contains\n> > multiple signatures.\n> \n> Thanks for discovering this.  Do you mind if I take this conversation\n> to the public mailing list?  (I'd bounce the existing thread there if\n> that's okay with you.)\n> \n\nI've already asked somewhere else in the thread if you consider this\nsuitable for disclosure, and haven't received a reply yet.  In any case,\nI don't mind it.  I can resend my patch there if necessary too.\n\n-- \nBest regards,\nMichał Górny\n"}]}