From: Jonathan Nieder Date: Wed, 15 Aug 2018 21:20:09 GMT Subject: Re: Potential vulnerability: 'mixed up' output when commit has multiple signatures Message-ID: <20180815212009.GE181377@aiede.svl.corp.google.com> In-Reply-To: <1534315421.1603.0.camel@gentoo.org> Michał Górny wrote: > On Tue, 2018-08-14 at 22:35 -0700, Jonathan Nieder wrote: > > Michał Górny wrote: >>> I've been testing the git signature verification a bit and I've >>> discovered a troubling behavior when the commit object contains >>> multiple signatures. >> >> Thanks for discovering this. Do you mind if I take this conversation >> to the public mailing list? (I'd bounce the existing thread there if >> that's okay with you.) > > I've already asked somewhere else in the thread if you consider this > suitable for disclosure, and haven't received a reply yet. In any case, > I don't mind it. Thanks, doing so. Thanks again for the analysis and fix as well.