http://www.mjsite.com saves this page so readers can view old news that may not still be availible elsewhere.
This is a saved page of Security hole found in crypto program GPG (InfoWorld)
This is a copy we made of the page on 30-Mar-2006.
The original page may or may not still be availible and pictures and text may have changed since then.
Click Here to view the original page at the original website.


Security hole found in crypto program GPG | InfoWorld | News | 2006-03-13 | By James Niccolai, IDG News Service
About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld InfoWorld HomeTechnology NewsTechnology Test CenterOpinionsTechnology Product GuideTechnology IndexCareers
 SPECIAL REPORTS  RSS FEEDS
SiteIT Product Guide Search
 
Free Technology Newsletters
Technology & Business Daily
SOA Report

Security hole found in crypto program GPG

Attackers could sneak malicious code into e-mails

By James Niccolai, IDG News Service
March 13, 2006
E-mailE-mail  

Developers of the open-source GnuPG encryption software have reported a security flaw that could allow an attacker to sneak malicious code into a signed e-mail message.

Free IT resource

InfoWorld's SOA Executive Forum: Lessons From the Front Lines

Sponsored by InfoWorld

Free IT resource

OPEN ENTERPRISE SPOTLIGHT

Sponsored by Novell, Dell and My SQL

GnuPG, or Gnu Privacy Guard, is an open-source version of the PGP (Profile, Products, Articles) encryption program used for encrypting data and creating digital signatures. It's included with several Linux (Overview, Articles, Company) distributions as well as the open-source FreeBSD operating system, and is also used widely used by the IT security industry.

The vulnerability allows an attacker to take a signed message and insert additional code, which then appears to the recipient as if it were part of the digitally signed content.

"Someone who's able to intercept the message as it's transmitted could inject some data, and then the person who verifies the signature would be told it's a valid, unaltered message," said Thomas Kristensen, chief technology officer with security vendor Secunia, in Copenhagen.

"That's one of the main purposes of the program, so it's quite significant," he added.

The attacker could potentially alter a text file, like a business contract, or an executable file attached to the message, he said. Secunia ranked the flaw as "moderately critical."

It affects all versions of GnuPG prior to 1.4.2.2, and users are advised to upgrade at once to that release. More information is on the GnuPG Web site at http://lists.gnupg.org/pipermail/gnupg-announce/2006q1/000216.html

The GnuPG team uncovered the flaw while testing the patch for a previous vulnerability reported last month. That flaw could have led to false positives when verifying signature files. Upgrading to the 1.4.2.2 release fixes that problem as well, the group said.

GPG is "fairly widely used among certain communities," although most people today probably use the encryption features in Microsoft (Profile, Products, Articles) Windows, Kristensen said.

The two recent security holes are unlikely to damage GPG's credibility, he said.

"People know it's still sound in the way it was designed and programmed, most people would consider this a minor oversight that's been corrected in a way you'd expect from a serious open-source project like GPG," Kristensen said.




E-mailE-mail  



TOP NEWS:


» US diplomats intervene in Microsoft EU case
The action came as the company's top lawyers arrived in Brussels to make a final attempt to convince regulators not to impose daily fines

» Sprint Nextel outlines 3G expansion, upgrade
The Sprint Power Vision network uses EV-DO and will expand to cover an estimated 190 million people by the end of this year, the company said

» Gateway introduces new skinny notebooks
The E-100M is Gateway's first "ultraportable" since the Model 200 in 2002

» Microsoft fails in Oracle, Sun subpoena bid
Judge denies Microsoft's request for access to Oracle and Sun documents for its case with the EU

» Nokia ups forecast for worldwide mobile phone sales
Company also details new tool to encourage users in emerging markets

» German bank fights phishing with electronic signatures
Postbank to begin attaching electronic signature to all e-mail correspondence with customers




STORAGE AREA NETWORK (SAN) SOLUTIONS
Join us for a live Webcast and learn from Tony Asaro and James Lundsford how they made a fast and easy transition from their DAS to a SAN solution. Sponsored by NetApp.

»  Click here to view this Webcast
  SPYWARE
Unwanted software is running rampant in today's enterprises, and spyware is evolving faster than its countermeasures. This newly updated IT Strategy Guide will show you what can be done about it. Sponsored by Sophos.

» Click here to download now


- Special Advertising Partners -
WHITE PAPERS
 
>> WHITE PAPERS LIBRARY

WHITE PAPERS E-MAIL ALERT

Find out when the latest white paper is available:

 

»  HA VENDOR REQUIREMENTS WHITE PAPER - No matter how comprehensive the high availability product and no matter how intuitive its user interface, ensuring the high availability of a mission-critical environment is an intricate process. To ...
»  BUSINESS DRIVERS FOR HA WHITE PAPER - Businesses have many applications that just can't be down. These applications serve clients, supply chains or control the transfer of funds. If these systems are unavailable, the business feels the ...
»  HA TECHNOLOGY REQUIREMENTS WHITE PAPER - Unplanned downtime can happen when you least expect it and when you can least afford it and in a world where planned downtime for scheduled maintenance is frequent and certain, high availability ...
»  Business Value of Reducing the Costs and Risks of e-Discovery and Regulatory Compliance
»  The Benefits of Continuous Data Protection
»  Sonic ESB: An Architecture and Lifecycle Definition

 
MORE APPLICATION DEVELOPMENT WHITE PAPERS


WHITE PAPERS BY TOPIC


Application development
Applications
Business
Hardware
Networking
Platforms
Security
Standards
Storage
Telecom
Web services
Wireless
» Efficient load testing of Web Applications
A description of the characteristics automated test tools must have for efficient testing of complex ...
» Step-by-Step Guide to Testing Your Web Application
This checklist for testing web applications covers the most critical items in making sure a web ...
» Darning SOX: Governance Elements of Sarbanes-Oxley
SOX contains provisions relating to numerous aspects of corporate transparency. This paper covers ...
» Prove Control of the Infrastructure Using Tripwire
An organization's success is linked to the reliability, availability and security of IT. Management ...
» Infrastructure Integrity
IT managers need to build a solid foundation upon which a coherent, secure, and functional network ...

 
SPONSORED LINKS  

»  Verizon Business - Total capability backed by accountability
»  CA - Unlock the Value of IT with CA Service Management
»  JBoss - Learn how to evaluate the financial impact of open source. Go!
»  SGI - Download SGI’s white paper: HPC Meets Databases.
»  SSA Global - Start responding to customer demand in real time. Now.
 


 

FREE SUBSCRIPTION


Order today to get your FREE subscription (a $195 value!) to InfoWorld magazine, the weekly publication that provides indispensable product information to IT professionals.

NOTE: Complimentary subscriptions sent only to those applicants who qualify.

First Name:
Last Name:
Company Name:
Title:
Mailing Address:
City:
State/Province:
Zip/Postal Code:
Email Address:


NOTE: Offer valid in U.S. and Canada only
Non-U.S. click here

SEE ALSO

TAGS:

security 
» COMPLETE LIST OF TAGS

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX

TECH WATCH 


'Our iPods only go up to 6'
Apple has introduced music volume capping to its iPods following concerns about its effect on peoples' hearing. Okay, so the headline is a lame reference to 1984 comedy "This is Spinal Tap's" dialogue where Nigel said the mock band's amps went up ...

You know the Web's broken when....
Two recent data points that shed some interesting light on the Web site phishing epidemic: one is a little survey done by the fine folks at F-Secure earlier today of top-level domains (TLDs) that contain the names of common banks or online commerce ...

JON UDELL'S CORNER 


Jon Udell's Column and Blog Dealing with technological diversity
(InfoWorld) - Tom Standage’s history of telegraphy, The Victorian Internet, draws striking parallels between that era’s communication ...

Jon's Blog | Jon's Column

COLUMNISTS

Edge Dynamics puts SaaS on a critical mission
Ephraim Schwartz's Column and Blog (InfoWorld) - Edge Dynamics, a company that analyzes transactional data for the pharmaceutical industry, is planting its flag...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Zero Day 
Laptop Theft, cellphone eavesdropping and phishing attack (sort of)
Okay, I'll agree with this week's column by Oliver Rist on not blaming the laptop for data theft (but please don't tell ...

ProdBlog 
IBM to roll 3Com VOIP solution into System i
IBM and 3Com announced plans on Thursday to offer the 3Com VCX suite of IP telephony solutions on IBM's "all-in-one" ...




IDG ENTERPRISE NETWORK
Cisco's version of the future of secure networks  (TechWorld)
Microsoft roars into VoIP market  (TechWorld)

GOVERNMENT IT & POLICY
High Court Considers EBay Case On Patent
House Approves Comp Time for Justice Department Lawyers
Internet Firms Want FCC to Enforce Net Neutrality

ADVERTISEMENT


 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX  CAREERS   About :: Advertise :: Subscribe :: Contact Us :: Awards :: Events 

Copyright © 2006, Reprints, Permissions, Licensing, IDG Network, Privacy Policy.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO :: Bio-IT World
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no :: IDG.pl