git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Potential vulnerability: 'mixed up' output when commit has multiple signatures

From
Michał Górny <mgorny@gentoo.org>
Date
Aug 15, 2018, 06:43 UTC
Message-ID
<1534315421.1603.0.camel@gentoo.org>
In-Reply-To
<20180815053522.GI32543@aiede.svl.corp.google.com>
On Tue, 2018-08-14 at 22:35 -0700, Jonathan Nieder wrote:
Show 12 quoted lines
> Hi,
> 
> Michał Górny wrote:
> 
> > I've been testing the git signature verification a bit and I've
> > discovered a troubling behavior when the commit object contains
> > multiple signatures.
> 
> Thanks for discovering this.  Do you mind if I take this conversation
> to the public mailing list?  (I'd bounce the existing thread there if
> that's okay with you.)
> 

I've already asked somewhere else in the thread if you consider this suitable for disclosure, and haven't received a reply yet. In any case, I don't mind it. I can resend my patch there if necessary too.

-- 
Best regards,
Michał Górny
Next: Jonathan Nieder
Message 1 of 2 in “Re: Potential vulnerability: 'mixed up' output when commit has multiple signatures”
  1. Michał GórnyAug 15, 2018
  2. Jonathan NiederAug 15, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.