LWN.net Logo

SquirrelMail 1.4.13 released - older versions compromised

SquirrelMail 1.4.13 released - older versions compromised

Posted Dec 17, 2007 18:03 UTC (Mon) by proski (subscriber, #104)
In reply to: SquirrelMail 1.4.13 released - older versions compromised by wahern
Parent article: SquirrelMail 1.4.13 released - older versions compromised

I'm afraid you don't get it. Saying that the attacker must pick both files means that the attacker would need to influence the original file in addition to the one created by the attacker. If the attacker can add random data to the original tarball, we have a bigger problem, and the checksum is irrelevant.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds