ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 8 sources: “gpg.fail authors' GnuPG retrospective reveals disputed 0-day RCE in gpgsm 2.4.9 via printf format-string flaw” — merged summary and timeline →

Re: Retrospective by 'gpg.fail' authors

infoResearchimportance 25
AI summary · glm-5.3-flash

GnuPG maintainer Werner Koch responds on oss-security to a gpg.fail retrospective covering 2003-era GnuPG code.

On oss-security, GnuPG lead developer Werner Koch replied to a retrospective published by the gpg.fail authors, citing a December 2003 commit in GnuPG's gettime.c affecting asctimestamp and printf format attributes in util.h. The excerpt contains no new CVE identifiers or exploitation evidence, and appears to revisit long-standing historical GnuPG code paths discussed by the retrospective's authors.

  • Thread revisits a 2003 GnuPG commit in gettime.c, including asctimestamp and printf format attribute changes.
  • Written by Werner Koch in response to a retrospective by the gpg.fail authors on oss-security.
VendorsGnuPG
Organizationsgpg.fail

Indicators of compromiseAll →

TypeIndicatorContext
sha18ab35a7d26707dfa0032b3b0dbde6a984a9683cbtime and that part of the code was simply forgotten: commit 8ab35a7d26707dfa0032b3b0dbde6a984a9683cb Author: Werner Koch AuthorDate: Wed Dec 17 12:26:38 2003 +0
Full article

Posted by Werner Koch on Sep 16 On Wed, 16 Sep 2026 02:27, Sam James said: Yes, sure. But 2003 was a different time and that part of the code was simply forgotten: commit 8ab35a7d26707dfa0032b3b0dbde6a984a9683cb Author: Werner Koch AuthorDate: Wed Dec 17 12:26:38 2003 +0000 * gettime.c (asctimestamp): Add a note on a non-avoidable gcc warning. * util.h [!HAVE_VASPRINTF]: Add printf format attribute to the replacement...

This source does not provide full text. Read it at seclists.org.