OpenPGP Private Key Attack Vulnerability
BID:2673
Info
OpenPGP Private Key Attack Vulnerability
| Bugtraq ID: | 2673 |
| Class: | Design Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Unknown |
| Published: | Mar 20 2001 12:00AM |
| Updated: | Mar 20 2001 12:00AM |
| Credit: | Discovered by Vlastimil Klima and Tomas Rosa of ICZ and published in a press release on March 20, 2001. |
| Vulnerable: |
Network Associates PGP 7.0.3 Network Associates PGP 6.5.8 Network Associates PGP 6.5.3 Network Associates PGP 6.0.2 Network Associates PGP 5.5.5 Network Associates PGP 5.0 GNU GNU Privacy Guard 1.0.4 GNU GNU Privacy Guard 1.0.3 b GNU GNU Privacy Guard 1.0.3 GNU GNU Privacy Guard 1.0.2 GNU GNU Privacy Guard 1.0.1 GNU GNU Privacy Guard 1.0 |
| Not Vulnerable: |
GNU GNU Privacy Guard 1.0.5 |
Discussion
OpenPGP Private Key Attack Vulnerability
The OpenPGP Message Format Standard provides information on the message-exchange packet formats used by OpenPGP to provide encryption, decryption, signing, and key management functions. Many of the techniques described in the standard have been adopted into widely-used public key encryption programs.
Two cryptologists, Vlastimil Klima and Tomas Rosa, have found a flaw in the OpenPGP key format which could make it possible for an adversary to forge a PGP signature using a victim's private key without knowing the pass phrase for that key.
The OpenPGP Message Format Standard provides information on the message-exchange packet formats used by OpenPGP to provide encryption, decryption, signing, and key management functions. Many of the techniques described in the standard have been adopted into widely-used public key encryption programs.
Two cryptologists, Vlastimil Klima and Tomas Rosa, have found a flaw in the OpenPGP key format which could make it possible for an adversary to forge a PGP signature using a victim's private key without knowing the pass phrase for that key.
Exploit / POC
OpenPGP Private Key Attack Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
OpenPGP Private Key Attack Vulnerability
References:
References:
- Attack on Private Signature Keys of the OpenPGP format (ICZ)
- OpenPGP Attack Press Release (in English) (ICZ)
- RFC 2440: OpenPGP Message Format (Internet Engineering Task Force)