Re: Potential vulnerability: 'mixed up' output when commit has multiple signatures
- From
Michał Górny <mgorny@gentoo.org>
- Date
- Aug 15, 2018, 06:43 UTC
- Message-ID
- <1534315421.1603.0.camel@gentoo.org>
- In-Reply-To
- <20180815053522.GI32543@aiede.svl.corp.google.com>
On Tue, 2018-08-14 at 22:35 -0700, Jonathan Nieder wrote:
Show 12 quoted lines
> Hi, > > Michał Górny wrote: > > > I've been testing the git signature verification a bit and I've > > discovered a troubling behavior when the commit object contains > > multiple signatures. > > Thanks for discovering this. Do you mind if I take this conversation > to the public mailing list? (I'd bounce the existing thread there if > that's okay with you.) >
I've already asked somewhere else in the thread if you consider this suitable for disclosure, and haven't received a reply yet. In any case, I don't mind it. I can resend my patch there if necessary too.
-- Best regards, Michał Górny