Re: [PATCH v2 0/3] imap-send: modernize the OpenSSL API
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Mar 12, 2026, 00:25 UTC
- Message-ID
- <xmqqsea5lwqj.fsf@gitster.g>
- In-Reply-To
- <20260311221027.1404476-1-dev+git@drbeat.li>
Beat Bolli <dev+git@drbeat.li> writes:
> Changes vs v1: > - keep the check for embedded NUL characters
... which amounts to this difference, which is a lot more explicit way to express what is going on. I like it.
Thanks.
diff --git a/imap-send.c b/imap-send.c index 789055d7fd..af02c6a689 100644 --- a/imap-send.c +++ b/imap-send.c @@ -222,6 +222,11 @@ static int ssl_socket_connect(struct imap_socket *sock UNUSED, static int host_matches(const char *host, const ASN1_STRING *asn1_str) { const char *pattern = (const char *)ASN1_STRING_get0_data(asn1_str); + + /* embedded NUL characters may open a security hole */ + if (memchr(pattern, '\0', ASN1_STRING_length(asn1_str))) + return 0; + if (pattern[0] == '*' && pattern[1] == '.') { pattern += 2; if (!(host = strchr(host, '.')))