Re: Security findings

"Kevin J. McCarthy" <[email protected]>
Newsgroups gmane.mail.mutt.devel
Message-ID <aeRHibas1k0MWd5f@qinghai>
On Sun, Apr 19, 2026 at 07:48:40AM +0800, Kevin J. McCarthy wrote:
>On Sat, Apr 18, 2026 at 08:27:26PM +0200, Alejandro Colomar via Mutt-dev wrote:
>>>  kevin/stable-security-06        Fix imap_auth_gss() security_level size.
>>
>>I think the commit message should also say something about the change
>>from long to uint32_t.  It's weird that it has been working, considering
>>that long is usually 64-bits wide.  Was it really working by pure
>>accident?
>
>It's possible it isn't working at all.  The branch only happened for 
>passwords > 64 characters.

Err... sorry, it was early and I was getting my commits mixed up. :-D

The comments seem to indicate the buf_size isn't actually important:

   /* we don't care about buffer size if we don't wrap content. But here it is */
   [...]
   buf_size = htonl (buf_size); /* not relevant without integrity/privacy */

So I can only surmise that it was incorrect but neither side cared.

-- 
Kevin J. McCarthy
GPG Fingerprint: 8975 A9B3 3AA3 7910 385C  5308 ADEF 7684 8031 6BDA
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEiXWpszqjeRA4XFMIre92hIAxa9oFAmnkR4kACgkQre92hIAx
a9pr3g//QU1AKdw98/m9H2Wy2/z+qe2oHWlTnJ7ADhkyWJQWJ62XWJgHNaWNYf4s
RgqBAz+eDU92vTjL+lRNJqmUPoBXQdRuZQpNhflLRYSfYGT+/HJAd3ww/cM2sd/N
KYhv0n2u5M31CYOLHrZp8HxsVHH2vuHKy5fiYbsKw+gE2qltdSr9p97NnxOKtDOx
Af4g4SpF+tgC8/Bz9gga1gBGSMD5XpmCru+SGKe8pcwZajAnspT8Ols0jPh/PoVH
kZvfrXSkanupeC4pAspw9KOVzfdSq8q8izYT9qrw9p/2urfB//lVdlICQ03Fbeul
fSeBY4wpJeUJrjlOTcjgYJeVSa/R72Bu/w+tswWDidPvzL+DMABvUwBub2ikinA3
n/Zuz9MjJhzsVElzzoPkBL3tzRq34W4Z/3Nsr7J/BsQBqezDmTzFtKzE5FqNQdA9
27OwdCZYBqtAAst+Pj3CUDo5V7b+LvCtO8+IwH+pm6Rcf4vYyxDqwvxZS102Wwug
L1g37bH29X8udKuKPTXLrW55z7DAuuHvej0w52QkMdZDoZHtm/Jbhnm0+D9li3sD
JKWym9SpfAsTJMO/xu4G8OOtlUY1TyAeyxvgcqOYHX45ugXY07nDWQLemLSWK939
uGjgaIs0KoBDPq6/0mHmtKO1hWETHluWr+QCYu3PrvIDcfQg9AM=
=B8hv
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.