Update Your GPG

If you use PGP, the free PGP replacement, then you need to update your software due to a huge security hole.

ITPro Today

March 13, 2006

1 Min Read
ITPro Today logo in a gray background | ITPro Today

If you use PGP, the free PGP replacement, then you need to update your software to v1.4.2.2 due to a huge security hole that allows injection of unsigned data. Tavis Ormandy discovered the problem and reported it to the developers.

In summary, "Signature verification of non-detached signatures may give a positive result but when extracting the signed data, this data may be prepended or appended with extra data not covered by the signature. Thus it is possible for an attacker to take any signed message and inject extra arbitrary data."

Read the technical nitty gritty here, and get the latest version here .


Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like