git.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Re: Potential vulnerability: 'mixed up' output when commit has multiple signatures
       [not found] ` <20180815053522.GI32543@aiede.svl.corp.google.com>
@ 2018-08-15  6:43   ` Michał Górny
  2018-08-15 21:20     ` Jonathan Nieder
  0 siblings, 1 reply; 2+ messages in thread
From: Michał Górny @ 2018-08-15  6:43 UTC (permalink / raw)
  To: Jonathan Nieder; +Cc: git-security

[-- Attachment #1: Type: text/plain, Size: 692 bytes --]

On Tue, 2018-08-14 at 22:35 -0700, Jonathan Nieder wrote:
> Hi,
> 
> Michał Górny wrote:
> 
> > I've been testing the git signature verification a bit and I've
> > discovered a troubling behavior when the commit object contains
> > multiple signatures.
> 
> Thanks for discovering this.  Do you mind if I take this conversation
> to the public mailing list?  (I'd bounce the existing thread there if
> that's okay with you.)
> 

I've already asked somewhere else in the thread if you consider this
suitable for disclosure, and haven't received a reply yet.  In any case,
I don't mind it.  I can resend my patch there if necessary too.

-- 
Best regards,
Michał Górny

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 963 bytes --]

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: Potential vulnerability: 'mixed up' output when commit has multiple signatures
  2018-08-15  6:43   ` Potential vulnerability: 'mixed up' output when commit has multiple signatures Michał Górny
@ 2018-08-15 21:20     ` Jonathan Nieder
  0 siblings, 0 replies; 2+ messages in thread
From: Jonathan Nieder @ 2018-08-15 21:20 UTC (permalink / raw)
  To: Michał Górny; +Cc: git

Michał Górny wrote:
> On Tue, 2018-08-14 at 22:35 -0700, Jonathan Nieder wrote:
> > Michał Górny wrote:

>>> I've been testing the git signature verification a bit and I've
>>> discovered a troubling behavior when the commit object contains
>>> multiple signatures.
>>
>> Thanks for discovering this.  Do you mind if I take this conversation
>> to the public mailing list?  (I'd bounce the existing thread there if
>> that's okay with you.)
>
> I've already asked somewhere else in the thread if you consider this
> suitable for disclosure, and haven't received a reply yet.  In any case,
> I don't mind it.

Thanks, doing so.

Thanks again for the analysis and fix as well.

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2018-08-15 21:20 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] <1533898313.1249.36.camel@gentoo.org>
     [not found] ` <20180815053522.GI32543@aiede.svl.corp.google.com>
2018-08-15  6:43   ` Potential vulnerability: 'mixed up' output when commit has multiple signatures Michał Górny
2018-08-15 21:20     ` Jonathan Nieder

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).