ZeroHour
oss-securitypublished ()ingested 1
Part of a story covered by 9 sources: “'gpg.fail' GnuPG retrospective reveals disputed printf format-string 0-day in gpgsm 2.4.9, sparks legacy-code debate” — merged summary and timeline →

Re: Retrospective by 'gpg.fail' authors

infoVulnerabilityimportance 12
AI summary · glm-5.3-flash

oss-security follow-up to a gpg.fail authors' retrospective argues that GnuPG's unmaintained, forgotten code is a security liability and should be deleted.

On the oss-security mailing list, Soatok Dreamseeker responds to a retrospective published by the gpg.fail authors, asking why unmaintained code is retained and stating that forgotten, unmaintained code is a liability and effectively unmaintained by definition. The visible reply addresses Werner Koch and concerns GnuPG code maintenance. No specific CVE, flaw, or exploitation is described in this snippet.

  • Reply to a retrospective by the gpg.fail authors on oss-security
  • Commenter urges deleting unmaintained GnuPG code as a security liability
  • No concrete CVE or flaw detailed in this thread message
VendorsGnuPG
Full article

Posted by Soatok Dreamseeker on Sep 16 Hi Werner, So... why not delete it? Unmaintained code is a liability (and, categorically, forgotten about code is not being maintained).

This source does not provide full text. Read it at seclists.org.