Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: kgpg
Date: Mon, 11 Nov 2002 13:08:08
Message-Id: 20021110135533.DE15C3392C@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200211-002
6 - - --------------------------------------------------------------------
7
8 PACKAGE : kgpg
9 SUMMARY : keys generated in wizard have an empty passphrase
10 DATE    : 2002-11-10 13:11 UTC
11 EXPLOIT : local
12
13 - - --------------------------------------------------------------------
14
15 - From http://devel-home.kde.org/~kgpg/bug.html
16
17 A bug in Kgpg's key generation affects all secret keys generated
18 through Kgpg's wizard. (Bug does not affect keys created in
19 console/expert mode). All keys created through the wizard have an
20 empty passphrase, which means that if someone has access to your
21 computer and can read your secret key, he/she can decrypt your files
22 whitout the need of a passphrase.
23
24 SOLUTION
25
26 It is recommended that all Gentoo Linux users who are running
27 app-crypt/kgpg-0.8.2 and earlier update their systems as follows:
28
29 emerge rsync
30 emerge kgpg
31 emerge clean
32
33 - - --------------------------------------------------------------------
34 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
35 hannes@g.o
36 - - --------------------------------------------------------------------
37 -----BEGIN PGP SIGNATURE-----
38 Version: GnuPG v1.0.7 (GNU/Linux)
39
40 iD8DBQE9zmVTfT7nyhUpoZMRAlGnAKCqIwAhxi/OtU55GVFWc+waeIY7LwCgtRgf
41 jglVyBs6JzNtzNEQZfz69nA=
42 =EybQ
43 -----END PGP SIGNATURE-----