Re: Certificate validation vulnerability in Git

2013-02-25 Thread Zubin Mithra
On Mon, Feb 25, 2013 at 8:46 AM, Jeff King p...@peff.net wrote: On Sun, Feb 24, 2013 at 11:01:50PM +0530, Zubin Mithra wrote: There seems to be a security issue in the way git uses openssl for certificate validation. Similar occurrences have been found and documented in other open source

Certificate validation vulnerability in Git

2013-02-24 Thread Zubin Mithra
. This is not performed. Kindly fix these issues, file a CVE and credit it to Dhanesh K. and Zubin Mithra. Thanks. We are not subscribed to this list, so we'd appreciate it if you could CC us in the replies. Hope this helps. Thanks! Zubin [1] http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf

Re: Certificate validation vulnerability in Git

2013-02-24 Thread Zubin Mithra
Hello, On Mon, Feb 25, 2013 at 12:16 AM, Andreas Ericsson a...@op5.se wrote: On 02/24/2013 06:31 PM, Zubin Mithra wrote: Hello, There seems to be a security issue in the way git uses openssl for certificate validation. Similar occurrences have been found and documented in other open source