ZeroHour
oss-securitypublished ()ingested 1
Part of a story covered by 4 sources: “gpg.fail retrospective RCE claim in gpgsm 2.4.9 disputed by GnuPG's Werner Koch: only a segfault reproduced” — merged summary and timeline →

Re: Retrospective by 'gpg.fail' authors

infoResearchimportance 15
AI summary · glm-5.3

Peter Gutmann replies to gpg.fail retrospective, pointing to PGP's arbitrary packet format as root of many past vulnerabilities.

Peter Gutmann posted a follow-up on oss-security referencing an Hacker News discussion of the gpg.fail authors' retrospective. The thread argues that a recurring source of severe PGP vulnerabilities is the format's permissive packet system, where a PGP message is a practically arbitrary stream of packets. This is discussion and retrospective analysis rather than a new disclosure.

  • Mailing-list reply discussing PGP packet-format design weaknesses
  • References gpg.fail retrospective and Hacker News thread
  • No new vulnerability or CVE disclosed in the reply
Full article

Posted by Peter Gutmann on Sep 13 Sam James writes: https://news.ycombinator.com/item?id=46404339 which begins: A thru-line of some of the gnarliest vulnerabilities here is PGP's insane packet system, where a PGP message is a practically arbitrary stream of...

This source does not provide full text. Read it at seclists.org.