MD5 value security consideration
Graham Klyne <[email protected]>
| Newsgroups | gmane.ietf.medfree |
|---|---|
| Message-ID | <[email protected]> |
I noticed this in a recent I-D, and thought it might appropriate to mention something similar in the security considerations of our drafts that suggest use of MD5. Implementations should take care not to assume that the value of the Content-MD5: header will always be 24 bytes or less - to avoid buffer overrun problems. It would also be unwise to assume that the characters in an arbitrary Content-MD5: header will be chosen from the base64 character set mandated by RFC 1864. #g ------------ Graham Klyne ([email protected])