[Full-disclosure] [gentoo-announce] [ GLSA 200503-29 ] GnuPG: OpenPGP protocol attack

From: Thierry Carrez (koon_at_gentoo.org)
Date: 03/24/05

  • Next message: Marc Deslauriers: "[Full-disclosure] [FLSA-2005:2155] Updated sharutils package fixes security issues"
    Date: Thu, 24 Mar 2005 22:52:14 +0100
    To: the_eye@drei.at
    
    
    
    

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 200503-29
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                                http://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

      Severity: Low
         Title: GnuPG: OpenPGP protocol attack
          Date: March 24, 2005
          Bugs: #85547
            ID: 200503-29

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    Automated systems using GnuPG may leak plaintext portions of an
    encrypted message.

    Background
    ==========

    GnuPG is complete and free replacement for PGP, a tool for secure
    communication and data storage.

    Affected packages
    =================

        -------------------------------------------------------------------
         Package / Vulnerable / Unaffected
        -------------------------------------------------------------------
      1 app-crypt/gnupg < 1.4.1 >= 1.4.1

    Description
    ===========

    A flaw has been identified in an integrity checking mechanism of the
    OpenPGP protocol.

    Impact
    ======

    An automated system using GnuPG that allows an attacker to repeatedly
    discover the outcome of an integrity check (perhaps by observing the
    time required to return a response, or via overly verbose error
    messages) could theoretically reveal a small portion of plaintext.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All GnuPG users should upgrade to the latest version:

        # emerge --sync
        # emerge --ask --oneshot --verbose ">=app-crypt/gnupg-1.4.1"

    References
    ==========

      [ 1 ] CERT VU#303094
            http://www.kb.cert.org/vuls/id/303094
      [ 2 ] CAN-2005-0366
            http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0366

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

      http://security.gentoo.org/glsa/glsa-200503-29.xml

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users machines is of utmost
    importance to us. Any security concerns should be addressed to
    security@gentoo.org or alternatively, you may file a bug at
    http://bugs.gentoo.org.

    License
    =======

    Copyright 2005 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    http://creativecommons.org/licenses/by-sa/2.0

    
    

    --
    gentoo-announce@gentoo.org mailing list
    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/

    --
    gentoo-announce@gentoo.org mailing list
    


  • Next message: Marc Deslauriers: "[Full-disclosure] [FLSA-2005:2155] Updated sharutils package fixes security issues"

    Relevant Pages

    • [Full-disclosure] [gentoo-announce] [ GLSA 200503-29 ] GnuPG: OpenPGP protocol attack
      ... Automated systems using GnuPG may leak plaintext portions of an ... encrypted message. ... GnuPG is complete and free replacement for PGP, ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Full-Disclosure)
    • [ GLSA 200503-29 ] GnuPG: OpenPGP protocol attack
      ... Automated systems using GnuPG may leak plaintext portions of an ... encrypted message. ... GnuPG is complete and free replacement for PGP, ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Bugtraq)
    • [Full-disclosure] [ GLSA 200503-29 ] GnuPG: OpenPGP protocol attack
      ... Automated systems using GnuPG may leak plaintext portions of an ... encrypted message. ... GnuPG is complete and free replacement for PGP, ... Security is a primary focus of Gentoo Linux and ensuring the ...
      (Full-Disclosure)
    • MDKSA-2001:053-1 - gnupg update
      ... A format string vulnerability exists in gnupg 1.0.5 and previous ... You can get the GPG public key of the Linux-Mandrake Security Team at ... Mandrake Linux 8.0: ...
      (Bugtraq)
    • Re: Dulles , Reagan Airports Add Free Wi-Fi
      ... must break into your home to gain access (if you have proper security.) ... Witopia or Overplay.net and nobody on the local wifi network will be ... Follow my storm chasing adventures at http://bigstormpicture.blogspot.com ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ ...
      (alt.cellular.verizon)