Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> We thank Werner Koch, lead developer of GnuPG, for the prompt response to our disclosure and the productive collaboration in adding suitable countermeasures.

"[...] If you are using a GnuPG version with a Libgcrypt version < 1.6.0, it is possible to mount the described side-channel attack on Elgamal encryption subkeys. [...]"

https://lists.gnupg.org/pipermail/gnupg-announce/2014q3/0003...



I'm a bit confused. The paper states:

"We have disclosed our attack to GnuPG developers under CVE-2014-3591, suggested suitable countermeasures, and worked with the developers to test them. GnuPG 1.4.19 and Libgcrypt 1.6.3 (which underlies GnuPG 2.x), containing these countermeasures and resistant to the key-extraction attack described here, were released concurrently with the first public posting of these results."

Basically that Libcrypt 1.6.3 underlies GnuPG 2.x. But when I check my system:

foo@bar:~$ gpg2 --version gpg (GnuPG) 2.0.22 libgcrypt 1.5.3

So I'm wondering why GnuPG 2.0.22 isn't using Libgcrypt 1.6.x?

I can see from your reference that I can upgrade to Libgcrypt 1.6.x but that it requires a rebuild of GnuPG, which I'd rather not deal with right now.


You sound like if you're going to build the binary manually (using an axe or something). Just compile the latest version for your system. Your distribution's package manager should be up-to-date by now.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: