OpenPGP presentation bug unscrambled
Signature verification vuln
Posted in Software & Security, 8th March 2007 19:32 GMT
Business whitepaper - Virtualization: the four key cost savings
A flaw in the way encryption programs present data to users makes it possible for a block of unsigned and unencrypted data to appear no different to users from encrypted data in a message.
The bug does not stem from a flaw in encryption but in the way in which OpenPGP, the standard for transmitting PGP-encrypted data, is interpreted by GnuPG "helpers" such as Enigmail and mail programs such as Evolution and KMail.
OpenPGP-compliant messages might be made up of multiple sections, some of which might not be encrypted. However, helpers and mail software packages fail to use the GnuPG API correctly to interpret where encrypted sections start and end. As a result you might "see the pretty icon telling you that the whole message is encrypted and signed whereas there is a section of it (text, image, binary, whatever) which isn't," the SANS Institute's Internet Storm Centre helpfully explains.
A new release of GnuPG and update to email client have been produced to address the issue, as explained in an advisory here. ®
Business whitepaper - Virtualization: the four key cost savings
An improved architecture for high-efficiency, high-density data centers
Ten cooling solutions to support high-density server deployment [WP42]
The Business Case for Virtualization
Preventive Maintenance Strategy for Data Centers [WP 124]

Global notebook sales finally beat desktops
Dell restructuring puts 2,000 Limerick jobs under threat
PS2 the most played console of 2008
Steve Jobs dismisses death rumours