oss-sec mailing list archives
ezmlm signature mangling [was: Re: CVE request: sympa (try again)]
From: Daniel Kahn Gillmor <dkg () fifthhorseman net>
Date: Sat, 12 May 2012 01:44:19 -0400
On 05/11/2012 02:03 PM, micah wrote:
ps - for some reason the previous message is formatted strange, so I'm sending this one without the signature
Comparing the received version of the message with its original source, it appears that the mailing list software (ezmlm?) mangled Micah's message by modifying the internal mime parts of the message, despite them being wrapped inside a multipart/signed block. This contravenes the relevant standards [0], which indicate that the data within a multipart/signed MIME part needs to be treated by any MTA as opaque. I don't know who updates ezmlm these days, but that probably needs to be addressed if there's an expectation that people should be able to send cryptographically-signed messages with non-ASCII text to the list. --dkg [0] https://tools.ietf.org/html/rfc3156#section-3
Current thread:
- CVE request: sympa (try again) micah (May 11)
- ezmlm signature mangling [was: Re: CVE request: sympa (try again)] Daniel Kahn Gillmor (May 11)
- Re: ezmlm signature mangling [was: Re: CVE request: sympa (try again)] Solar Designer (May 12)
- Re: CVE request: sympa (try again) Kurt Seifried (May 11)
- Re: CVE request: sympa (try again) micah anderson (May 12)
- Re: CVE request: sympa (try again) Kurt Seifried (May 12)
- Re: CVE request: sympa (try again) micah anderson (May 15)
- Re: CVE request: sympa (try again) Kurt Seifried (May 15)
- Re: CVE request: sympa (try again) micah anderson (May 12)
- ezmlm signature mangling [was: Re: CVE request: sympa (try again)] Daniel Kahn Gillmor (May 11)