Re: MD5 value security consideration

Graham Klyne <[email protected]>
Newsgroups gmane.ietf.medfree
Message-ID <[email protected]>
At 10:03 04/03/99 -0800, Bill Newman wrote:
>Graham Klyne wrote
>
>> I noticed this in a recent I-D, and thought it might appropriate to mention
>> something similar in the security considerations of our drafts that suggest
>> use of MD5.
>> 
>>    Implementations should take care not to assume that the value of the
>>    Content-MD5: header will always be 24 bytes or less - to avoid buffer
>>    overrun problems.  It would also be unwise to assume that the
>>    characters in an arbitrary Content-MD5: header will be chosen from
>>    the base64 character set mandated by RFC 1864.
>
>Perhaps I'm missing something, but this doesn't look like a special
>security consideration.  It seems to me that in both your I-D and
>mine, the possibility of buffer overflow or unexpected characters for
>hash values has the same security consequences as any other buffer
>overflow ...

I think you're right.  It's just that enough security holes have been
caused by implementation weaknesses in this area that it probably doesn't
harm to remind imlementers at every opportunity.

#g


------------
Graham Klyne
([email protected])
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.