Re: Security findings
"Kevin J. McCarthy" <[email protected]>
| Newsgroups | gmane.mail.mutt.devel |
|---|---|
| Message-ID | <aeRHibas1k0MWd5f@qinghai> |
On Sun, Apr 19, 2026 at 07:48:40AM +0800, Kevin J. McCarthy wrote: >On Sat, Apr 18, 2026 at 08:27:26PM +0200, Alejandro Colomar via Mutt-dev wrote: >>> kevin/stable-security-06 Fix imap_auth_gss() security_level size. >> >>I think the commit message should also say something about the change >>from long to uint32_t. It's weird that it has been working, considering >>that long is usually 64-bits wide. Was it really working by pure >>accident? > >It's possible it isn't working at all. The branch only happened for >passwords > 64 characters. Err... sorry, it was early and I was getting my commits mixed up. :-D The comments seem to indicate the buf_size isn't actually important: /* we don't care about buffer size if we don't wrap content. But here it is */ [...] buf_size = htonl (buf_size); /* not relevant without integrity/privacy */ So I can only surmise that it was incorrect but neither side cared. -- Kevin J. McCarthy GPG Fingerprint: 8975 A9B3 3AA3 7910 385C 5308 ADEF 7684 8031 6BDA
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEiXWpszqjeRA4XFMIre92hIAxa9oFAmnkR4kACgkQre92hIAx a9pr3g//QU1AKdw98/m9H2Wy2/z+qe2oHWlTnJ7ADhkyWJQWJ62XWJgHNaWNYf4s RgqBAz+eDU92vTjL+lRNJqmUPoBXQdRuZQpNhflLRYSfYGT+/HJAd3ww/cM2sd/N KYhv0n2u5M31CYOLHrZp8HxsVHH2vuHKy5fiYbsKw+gE2qltdSr9p97NnxOKtDOx Af4g4SpF+tgC8/Bz9gga1gBGSMD5XpmCru+SGKe8pcwZajAnspT8Ols0jPh/PoVH kZvfrXSkanupeC4pAspw9KOVzfdSq8q8izYT9qrw9p/2urfB//lVdlICQ03Fbeul fSeBY4wpJeUJrjlOTcjgYJeVSa/R72Bu/w+tswWDidPvzL+DMABvUwBub2ikinA3 n/Zuz9MjJhzsVElzzoPkBL3tzRq34W4Z/3Nsr7J/BsQBqezDmTzFtKzE5FqNQdA9 27OwdCZYBqtAAst+Pj3CUDo5V7b+LvCtO8+IwH+pm6Rcf4vYyxDqwvxZS102Wwug L1g37bH29X8udKuKPTXLrW55z7DAuuHvej0w52QkMdZDoZHtm/Jbhnm0+D9li3sD JKWym9SpfAsTJMO/xu4G8OOtlUY1TyAeyxvgcqOYHX45ugXY07nDWQLemLSWK939 uGjgaIs0KoBDPq6/0mHmtKO1hWETHluWr+QCYu3PrvIDcfQg9AM= =B8hv -----END PGP SIGNATURE-----