Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4FADF8B3.4070005@fifthhorseman.net>
Date: Sat, 12 May 2012 01:44:19 -0400
From: Daniel Kahn Gillmor <dkg@...thhorseman.net>
To: oss-security@...ts.openwall.com
Subject: ezmlm signature mangling [was: Re: CVE request: sympa (try again)]

On 05/11/2012 02:03 PM, micah wrote:
> ps - for some reason the previous message is formatted strange, so I'm
> sending this one without the signature

Comparing the received version of the message with its original source,
it appears that the mailing list software (ezmlm?) mangled Micah's
message by modifying the internal mime parts of the message, despite
them being wrapped inside a multipart/signed block.  This contravenes
the relevant standards [0], which indicate that the data within a
multipart/signed MIME part needs to be treated by any MTA as opaque.

I don't know who updates ezmlm these days, but that probably needs to be
addressed if there's an expectation that people should be able to send
cryptographically-signed messages with non-ASCII text to the list.

	--dkg

[0] https://tools.ietf.org/html/rfc3156#section-3

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.