Re: Potential vulnerability: 'mixed up' output when commit has multiple signatures
From: Michał Górny <hidden>
Date: 2018-08-15 21:20:35
On Tue, 2018-08-14 at 22:35 -0700, Jonathan Nieder wrote:
Hi, Michał Górny wrote:quoted
I've been testing the git signature verification a bit and I've discovered a troubling behavior when the commit object contains multiple signatures.Thanks for discovering this. Do you mind if I take this conversation to the public mailing list? (I'd bounce the existing thread there if that's okay with you.)
I've already asked somewhere else in the thread if you consider this suitable for disclosure, and haven't received a reply yet. In any case, I don't mind it. I can resend my patch there if necessary too. -- Best regards, Michał Górny