PGP / GnuPG Chosen Ciphertext Message Disclosure Vulnerability
BID:5446
Info
PGP / GnuPG Chosen Ciphertext Message Disclosure Vulnerability
| Bugtraq ID: | 5446 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2002 12:00AM |
| Updated: | Aug 12 2002 12:00AM |
| Credit: | Published by K. Jallad, J. Katz, and B. Schneier. |
| Vulnerable: |
Network Associates PGP Freeware 7.0.3 Network Associates PGP 7.1.1 Network Associates PGP 7.1 Network Associates PGP 7.0.4 Network Associates PGP 7.0.3 Network Associates PGP 7.0 Network Associates PGP 6.5.8 Network Associates PGP 6.5.3 i for Windows Network Associates PGP 6.5.3 Network Associates PGP 6.5.1 i for Unix Network Associates PGP 6.5.1 i Network Associates PGP 6.5 Linux Network Associates PGP 6.0.2 i Network Associates PGP 6.0.2 Network Associates PGP 5.5.5 Network Associates PGP 5.5.3 i for Windows Network Associates PGP 5.5.3 i Network Associates PGP 5.0 i Network Associates PGP 5.0 Linux Network Associates PGP 5.0 IETF OpenPGP RFC 2440 GNU GNU Privacy Guard 1.0.7 GNU GNU Privacy Guard 1.0.6 GNU GNU Privacy Guard 1.0.5 GNU GNU Privacy Guard 1.0.4 GNU GNU Privacy Guard 1.0.3 b GNU GNU Privacy Guard 1.0.3 GNU GNU Privacy Guard 1.0.2 GNU GNU Privacy Guard 1.0.1 GNU GNU Privacy Guard 1.0 |
| Not Vulnerable: | |
Discussion
PGP / GnuPG Chosen Ciphertext Message Disclosure Vulnerability
PGP and GnuPG are two popular implementations of the OpenPGP encryption specification.
A weakness in the OpenPGP specification, as implemented by both products, may allow an attacker to learn the plaintext contents of encrypted communications. While some degree of user interaction is required, the attack is very plausible against non-technical end users.
The weakness is based on a form of chosen ciphertext attack. A user of the vulnerable software must be enticed into decrypting a modified version of a valid message, which as been prepared by the attacker. The user must then disclose the results of this decryption to the attack, possibly as the results of social engineering. This information will allow the attacker to recover a portion of the original message.
It is not believed to be possible to exploit this weakness against message content which is compressed during the OpenPGP encryption process. Modified data will generally result in an error in the decompression process, which will be reported to the user under attack.
PGP and GnuPG are two popular implementations of the OpenPGP encryption specification.
A weakness in the OpenPGP specification, as implemented by both products, may allow an attacker to learn the plaintext contents of encrypted communications. While some degree of user interaction is required, the attack is very plausible against non-technical end users.
The weakness is based on a form of chosen ciphertext attack. A user of the vulnerable software must be enticed into decrypting a modified version of a valid message, which as been prepared by the attacker. The user must then disclose the results of this decryption to the attack, possibly as the results of social engineering. This information will allow the attacker to recover a portion of the original message.
It is not believed to be possible to exploit this weakness against message content which is compressed during the OpenPGP encryption process. Modified data will generally result in an error in the decompression process, which will be reported to the user under attack.
Exploit / POC
PGP / GnuPG Chosen Ciphertext Message Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PGP / GnuPG Chosen Ciphertext Message Disclosure Vulnerability
Solution:
This attack may be mitigated by ensuring that OpenPGP compression is used on all messages. Ensure that compression is enabled on client software, and avoid transmitting compressed files such as .ZIP archives which may not be compressed a second time.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This attack may be mitigated by ensuring that OpenPGP compression is used on all messages. Ensure that compression is enabled on client software, and avoid transmitting compressed files such as .ZIP archives which may not be compressed a second time.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PGP / GnuPG Chosen Ciphertext Message Disclosure Vulnerability
References:
References:
- A Chosen Ciphertext Attack against Several E-Mail Encryption Protocols (J. Katz and B. Schneier)
- Implementation of Chosen-Ciphertext Attacks against PGP and GnuPG (K. Jallad, J. Katz, and B. Schneier)