Re: Certificate validation vulnerability in Git

2013-02-25 Thread Zubin Mithra
On Mon, Feb 25, 2013 at 8:46 AM, Jeff King wrote: > On Sun, Feb 24, 2013 at 11:01:50PM +0530, Zubin Mithra wrote: > >> There seems to be a security issue in the way git uses openssl for >> certificate validation. Similar occurrences have been found and >> documented in ot

Re: Certificate validation vulnerability in Git

2013-02-24 Thread Zubin Mithra
Hello, On Mon, Feb 25, 2013 at 12:16 AM, Andreas Ericsson wrote: > On 02/24/2013 06:31 PM, Zubin Mithra wrote: >> Hello, >> >> There seems to be a security issue in the way git uses openssl for >> certificate validation. Similar occurrences have been found and >>

Certificate validation vulnerability in Git

2013-02-24 Thread Zubin Mithra
_result function. This is not performed. Kindly fix these issues, file a CVE and credit it to Dhanesh K. and Zubin Mithra. Thanks. We are not subscribed to this list, so we'd appreciate it if you could CC us in the replies. Hope this helps. Thanks! Zubin [1] http://www.cs.utexas.edu/~shmat/