ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 4 sources: “gpg.fail retrospective RCE claim in gpgsm 2.4.9 disputed by GnuPG's Werner Koch: only a segfault reproduced” — merged summary and timeline →

Retrospective by 'gpg.fail' authors

mediumResearchimportance 52
AI summary · glm-5.3

Authors of the gpg.fail GnuPG vulnerability set published a retrospective with talk recording, slides, and a repo PoC.

Sam James shares that the researchers behind the 'gpg.fail' set of GnuPG vulnerabilities have published a retrospective, including a talk recording and slides. The slides appear to mention an additional vulnerability not yet widely reviewed, and a proof-of-concept is available in their repository. This follows earlier discussion of the gpg.fail findings on oss-security.

  • Retrospective published for gpg.fail GnuPG vulnerabilities
  • Talk recording and slides made available
  • Slides hint at another vulnerability not yet reviewed
  • PoC available in the researchers' repo
Full article

Posted by Sam James on Sep 12 Hi, The authors of the 'gpg.fail' set of vulnerabilities have published a retrospective, previously discussed on this list [0]. A recording of the talk is available [1] as are slides [2]. They also mention another vulnerability in the slides that is in the talk but I've not seen that yet. A PoC is available in their repo [3]. (I've only made my way through the slides on an initial first pass, so I don't consider...

This source does not provide full text. Read it at seclists.org.