git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Certificate validation vulnerability in Git

From
ZMZubin Mithra <zubin.mithra@gmail.com>
Date
Feb 24, 2013, 17:31 UTC
Message-ID
<CAA5xPpmmZuMK7q3-pTOx4L6DxFtyw5HWYdH7kHEsK=96KM5kAQ@mail.gmail.com>
Hello,

There seems to be a security issue in the way git uses openssl for certificate validation. Similar occurrences have been found and documented in other open source projects, the research can be found at [1].

-=========]
- imap-send.c
Line 307
 307   ret = SSL_connect(sock->ssl);
 308   if (ret <= 0) {
 309     socket_perror("SSL_connect", sock, ret);
 310     return -1;
 311   }
 312

Certificate validation errors are signaled either through return values of SSL_connect or by setting internal flags. The internal flags need to be checked using the SSL_get_verify_result function. This is not performed.

Kindly fix these issues, file a CVE and credit it to Dhanesh K. and Zubin Mithra. Thanks.

We are not subscribed to this list, so we'd appreciate it if you could CC us in the replies.

Hope this helps.

Thanks! Zubin

[1] http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf
Next: Andreas Ericsson
Message 1 of 7 in “Certificate validation vulnerability in Git”
  1. Zubin MithraFeb 24, 2013
  2. Andreas EricssonFeb 24, 2013
  3. Zubin MithraFeb 25, 2013
  4. Jeff KingFeb 25, 2013
  5. Junio C HamanoFeb 25, 2013
  6. Jeff KingFeb 25, 2013
  7. Zubin MithraFeb 25, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.