LWN.net Logo

SquirrelMail 1.4.13 released - older versions compromised

SquirrelMail 1.4.13 released - older versions compromised

Posted Dec 17, 2007 16:52 UTC (Mon) by wahern (subscriber, #37304)
In reply to: SquirrelMail 1.4.13 released - older versions compromised by njs
Parent article: SquirrelMail 1.4.13 released - older versions compromised

It's a tarball. The attacker can insert any random data he pleases in creating the collision.


(Log in to post comments)

SquirrelMail 1.4.13 released - older versions compromised

Posted Dec 17, 2007 18:03 UTC (Mon) by proski (subscriber, #104) [Link]

I'm afraid you don't get it. Saying that the attacker must pick both files means that the attacker would need to influence the original file in addition to the one created by the attacker. If the attacker can add random data to the original tarball, we have a bigger problem, and the checksum is irrelevant.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds