Thread (6 messages) flat view 6 messages, 3 authors, 2016-06-15

Re: Certificate validation vulnerability in Git

From: Jeff King <hidden>
Date: 2016-06-15 22:56:15

On Sun, Feb 24, 2013 at 07:46:51PM +0100, Andreas Ericsson wrote:
The lack of certificate authority verification presents no attack vector
for git imap-send. As such, it doesn't warrant a CVE. I'm sure you'll
be credited with a "reported-by" line in the commit message if someone
decides to fix it though. Personally, I'm not fussed.
Sure it presents an attack vector. I can man-in-the-middle your
imap-send client and read your otherwise secret patches. Or your
otherwise secret imap password.

-Peff
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help