]> dgit.raspbian.org Git - dovecot.git/commitdiff
[PATCH 2/2] doveadm: Avoid leaking doveadm_password or doveadm_api_key lengths
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Mon, 27 Apr 2026 22:51:01 +0000 (01:51 +0300)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
Gbp-Pq: Name 0002-doveadm-Avoid-leaking-doveadm_password-or-doveadm_ap.patch

src/doveadm/client-connection-http.c
src/doveadm/client-connection-tcp.c

index dfbc3528d7a68a5d666dc295706a3047e1f1d853..f083ac6e14f29a5e7c99b65b97133716b703a0f6 100644 (file)
@@ -973,7 +973,7 @@ doveadm_http_server_auth_basic(struct client_request_http *req,
        b64_value = t_base64_encode_str(0, UINT_MAX, value);
 
        if (creds->data != NULL &&
-           str_equals_timing_almost_safe(str_c(b64_value), creds->data))
+           str_equals_hash_timing_safe(str_c(b64_value), creds->data))
                return TRUE;
 
        e_error(conn->conn.event,
@@ -999,7 +999,7 @@ doveadm_http_server_auth_api_key(struct client_request_http *req,
 
        b64_value = t_base64_encode_str(0, UINT_MAX, set->doveadm_api_key);
        if (creds->data != NULL &&
-           str_equals_timing_almost_safe(creds->data, str_c(b64_value)))
+           str_equals_hash_timing_safe(creds->data, str_c(b64_value)))
                return TRUE;
 
        e_error(conn->conn.event,
index cb16f7214b43795fff26c2cdfa358f6cd937962d..b374028c971039962e74c63410c175075e5fcee9 100644 (file)
@@ -400,7 +400,7 @@ client_connection_tcp_authenticate(struct client_connection_tcp *conn)
                return -1;
        }
        pass = t_strndup(data + 9, size - 9);
-       if (!str_equals_timing_almost_safe(pass, set->doveadm_password)) {
+       if (!str_equals_hash_timing_safe(pass, set->doveadm_password)) {
                e_error(conn->conn.event,
                        "doveadm client authenticated with wrong password");
                return -1;