Re: [PATCH] Fix IMAP auth_crm MD5 digest of secret to use memcpy().

"Kevin J. McCarthy" <[email protected]>
Newsgroups gmane.mail.mutt.devel
Message-ID <aeVga9FWCJI46qfl@qinghai>
On Sun, Apr 19, 2026 at 05:08:29PM +0200, Rene Kita wrote:
>On Sun, Apr 19, 2026 at 01:50:51PM +0800, Kevin J. McCarthy wrote:
>> For a secret longer that MD5_BLOCK_LEN, an MD5 digest is used
>
>s/that/than

Ack.  Thank you.

>The part after the else above is:
>  strfcpy((char *) secret, password, sizeof(secret));
>
>Are we dealing here with strings or with buffers of bytes/chars?

Alex answered, but just to concur.  We are dealing with bytes for the 
output of md5_buffer().  But the password parameter is a string.

-- 
Kevin J. McCarthy
GPG Fingerprint: 8975 A9B3 3AA3 7910 385C  5308 ADEF 7684 8031 6BDA
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEiXWpszqjeRA4XFMIre92hIAxa9oFAmnlYGsACgkQre92hIAx
a9r8NBAA8jaKbxBYidBWs8+iS7gJGLyrMQjMs21XVd+0Ovcp0FoHSEfcSB4qxDQq
nWxrym5k4BSxdTnYtBOIjVhXZGKvCDShXXcK1ScRiNA/N3fSUJjNKl2dsFXYU4aH
XeGZfb15HhPX6XA5syAWrvgS4cHGRY+zFhNlJFul0g1hQF8MKx6jUYMvSvZuam9e
U+9SY/j9q89VFSR+s4R7BwNEBUWEsN6htxpkSLbSxecQZeCGvL6gnwAzQF3nmovo
S1UFmpyMDoDiBnnnGdL2JtEr/nFYvgZvsR2oUdwNi4GAAXTDeVGArZcnEuv8LJd5
Pswn9tCcUIdA4I+jugmGukA+FszNV3b2cd0FJRBq09g44gxgG09Pr4+shw48VBSA
1v0FYRKfTSWqy+mjjBMn6cGJHgcl9mHVODDJulKVlsydOpoAz71moiNk2LdKqDVj
b3aPoNZn35m6WQOLxNac2d4Cz1WVxSYq1JDzBSigjfInCK7cPONjJhSe1o23xDnu
ZQU9jUD2C9QAET9YE3YFMpmfpHlFBzA5BRM+F1Cs2wHpLVdW0F1FFX5wckbILBsH
VpxWB/dIvR7UOmyZagOVF3iYwRDoNuab7kHnHd1NEn8+CGBlYaUn1XYQ+74iaGRe
O/jvF3MOXhm24qpdwj1TsayN3Y1BVnGHO/9Z+7ixant0sKotHB0=
=Ykhy
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.