threads / discuss / 49139

Re: Potential vulnerability: 'mixed up' output when commit has multiple signatures

Subject: Re: Potential vulnerability: 'mixed up' output when commit has multiple signatures

## tl;dr

2 messages between Aug 15, 2018 and Aug 15, 2018.

replies: 1people: 2as markdown or json

Michał Górny· Aug 15, 2018, 06:43 UTC · lore
On Tue, 2018-08-14 at 22:35 -0700, Jonathan Nieder wrote:
Show 12 quoted lines
> Hi,
> 
> Michał Górny wrote:
> 
> > I've been testing the git signature verification a bit and I've
> > discovered a troubling behavior when the commit object contains
> > multiple signatures.
> 
> Thanks for discovering this.  Do you mind if I take this conversation
> to the public mailing list?  (I'd bounce the existing thread there if
> that's okay with you.)
> 

I've already asked somewhere else in the thread if you consider this suitable for disclosure, and haven't received a reply yet. In any case, I don't mind it. I can resend my patch there if necessary too.

-- 
Best regards,
Michał Górny
Jonathan Nieder· Aug 15, 2018, 21:20 UTC · re: Michał Górny · lore
Michał Górny wrote:
> On Tue, 2018-08-14 at 22:35 -0700, Jonathan Nieder wrote:
> > Michał Górny wrote:
Show 11 quoted lines
>>> I've been testing the git signature verification a bit and I've
>>> discovered a troubling behavior when the commit object contains
>>> multiple signatures.
>>
>> Thanks for discovering this.  Do you mind if I take this conversation
>> to the public mailing list?  (I'd bounce the existing thread there if
>> that's okay with you.)
>
> I've already asked somewhere else in the thread if you consider this
> suitable for disclosure, and haven't received a reply yet.  In any case,
> I don't mind it.
Thanks, doing so.
Thanks again for the analysis and fix as well.

← back to recent threads