MD5 value security consideration

Graham Klyne <[email protected]>
Newsgroups gmane.ietf.medfree
Message-ID <[email protected]>
I noticed this in a recent I-D, and thought it might appropriate to mention
something similar in the security considerations of our drafts that suggest
use of MD5.

   Implementations should take care not to assume that the value of the
   Content-MD5: header will always be 24 bytes or less - to avoid buffer
   overrun problems.  It would also be unwise to assume that the
   characters in an arbitrary Content-MD5: header will be chosen from
   the base64 character set mandated by RFC 1864.

#g

------------
Graham Klyne
([email protected])
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.