From: Junio C Hamano Date: Thu, 12 Mar 2026 00:25:40 GMT Subject: Re: [PATCH v2 0/3] imap-send: modernize the OpenSSL API Message-ID: In-Reply-To: <20260311221027.1404476-1-dev+git@drbeat.li> Beat Bolli writes: > Changes vs v1: > - keep the check for embedded NUL characters ... which amounts to this difference, which is a lot more explicit way to express what is going on. I like it. Thanks. diff --git a/imap-send.c b/imap-send.c index 789055d7fd..af02c6a689 100644 --- a/imap-send.c +++ b/imap-send.c @@ -222,6 +222,11 @@ static int ssl_socket_connect(struct imap_socket *sock UNUSED, static int host_matches(const char *host, const ASN1_STRING *asn1_str) { const char *pattern = (const char *)ASN1_STRING_get0_data(asn1_str); + + /* embedded NUL characters may open a security hole */ + if (memchr(pattern, '\0', ASN1_STRING_length(asn1_str))) + return 0; + if (pattern[0] == '*' && pattern[1] == '.') { pattern += 2; if (!(host = strchr(host, '.')))