git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Certificate validation vulnerability in Git

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 25, 2013, 05:35 UTC
Message-ID
<7v8v6d3qh8.fsf@alter.siamese.dyndns.org>
In-Reply-To
<20130225031847.GB31988@sigill.intra.peff.net>
Jeff King <peff@peff.net> writes:
Show 10 quoted lines
> On Sun, Feb 24, 2013 at 07:46:51PM +0100, Andreas Ericsson wrote:
>
>> The lack of certificate authority verification presents no attack vector
>> for git imap-send. As such, it doesn't warrant a CVE. I'm sure you'll
>> be credited with a "reported-by" line in the commit message if someone
>> decides to fix it though. Personally, I'm not fussed.
>
> Sure it presents an attack vector. I can man-in-the-middle your
> imap-send client and read your otherwise secret patches. Or your
> otherwise secret imap password.

Yes, the lack of verification alone will not hurt the victim; you would need to also be able to insert yourself in the middle, perhaps by poisoning the victim's DNS. But one of the points of using SSL/TLS is to resist such an attack, and it certainly is an attack surfce, even though it may be of a lessor kind than other kinds of attacks.

Previous: Jeff KingNext: Jeff King
Message 5 of 7 in “Certificate validation vulnerability in Git”
  1. Zubin MithraFeb 24, 2013
  2. Andreas EricssonFeb 24, 2013
  3. Zubin MithraFeb 25, 2013
  4. Jeff KingFeb 25, 2013
  5. Junio C HamanoFeb 25, 2013
  6. Jeff KingFeb 25, 2013
  7. Zubin MithraFeb 25, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.