3 msgUsing an old .gnupg directory
2 msgsubpacket of type 20 has critical bit set
59 msgQuestions about generating keys
1 msgPGPPublicKeyRing from Bouncy Castle package
2 msgDecrpytion not automatically possbible
15 msgCompression routines - please include 7-Zip
10 msgGnuPG & OpenSSH
1 msgA Passphrase Problem
14 msg[Announce] GnuPG 2.0.6 released
4 msgImporting a key from PGP

CoreLabs Detects Flaw In GnuPG - any comments ?
\ Eric Robinson (10 Aug 2007)
. \ David Shaw (10 Aug 2007)
. . \ Eric Robinson (10 Aug 2007)
. \ Florian Weimer (10 Aug 2007)

2 msgkey sizes: maximum size and shrinking
4 msgPartial file download issue - GPG
1 msgASP Shell and GnuPG
17 msgOpenPGP and usability
2 msggpgme: export key problems
1 msggpgme: A small introduction started
1 msggnupg 'unknown user' complaint about the subkey...
3 msggpg in a for loop
4 msgOpenPGP card on Javacard
Subject:CoreLabs Detects Flaw In GnuPG - any comments ?
Group:Gnupg-users
From:Eric Robinson
Date:10 Aug 2007


 
CoreLabs Detects Flaw In GnuPG
By CXOtoday Staff
Mumbai, Mar 9, 2007


Core Security Technologies has issued an advisory disclosing a flaw in
the GNU Privacy Guard (GnuPG or GPG). It is an OpenPGP- compliant
cryptographic software system and is a part of the Free Software
Foundation's (FSF) GNU software project, and third-party email
applications that rely on it for encrypted and signed email
communications.

CoreLabs, the research arm of Core Security, discovered this by
exploiting the vulnerability. According to the press release, issued by
Core Security, an attacker can add arbitrary content to encrypted and/or
signed emails in order to mislead recipients about the trustworthiness
of a message. In addition, attackers can use this flaw to bypass
content-filtering defenses, which makes it particularly inconvenient to
detect phishing attacks.

The company discovered that the scripts and applications using GnuPG are
prone to a vulnerability involving incorrect verification of signatures.
Unsuspecting users reading a GPG encrypted and/or signed email, using a
mail client or encryption extension, are led to believe that the entire
message was signed by the sender when, in fact, an arbitrary portion of
the content may have been inserted by an attacker.


In some cases, the attacker may completely hide the signed portion of a
message and present the user with only the forged portion. It should be
noted that this is not a cryptographic problem. It affects how
information is presented to the user and how third-party applications
interact with GnuPG.

This attack method infects systems using:

*GnuPG 1.4.6 and previous versions
*Enigmail 0.94.2 and previous versions
*KMail 1.9.5 and previous versions
*Evolution 2.8.1 and previous versions
*Sylpheed 2.2.7 and previous versions
*Mutt 1.5.13 and previous versions
*GNUMail 1.1.2 and previous versions
*Other scripts and applications using GnuPG may be vulnerable

To address this vulnerability, users of scripts and applications using
GnuPG should immediately upgrade to the latest versions of GnuPG and
Enigmail.

Additionally, Core Security recommends that, if a signed message looks
suspicious, the validity of the signature can be verified by manually
invoking GnuPG from the command line and adding the special option
"--status-fd" to gain extra information.

"This vulnerability is a good e.g. of how very subtle implementation
decisions on how to interface data communications between two
applications, in this case email front-end extensions and GnuPG, can end
up exposing end users to unexpected security weaknesses," said Iv n
Arce, CTO, Core Security Technologies. "We continue to encourage and
support the use of GnuPG as a convenient way to improve the security and
privacy of communications. To that effect and to prevent traffic
analysis attacks, we also recommend that encryption should be turned on
by default on every email."


------------------------------------------------------------------------
-----------------

Eric

-------------------------------------
Eric Robinson
Business Application Advisor
FedEx Corporate Services
Internet Engineering & EC Integration
901.263.5749
-------------------------------------

_______________________________________________
Gnupg-users mailing list
Gnupg-users
http://lists.gnupg.org/mailman/listinfo/gnupg-users


© 2004-2008 readlist.com