Mixed messages...
By Joris Evers
Published: 13 March 2006 08:25 GMT
A pair of security bugs in cryptography software could allow an attacker to insert content into a digitally signed message or forge signatures on files.
The flaws lie in the open-source GNU Privacy Guard software, also known as GnuPG and GPG, the GnuPG group said in two alerts. The software, a free replacement for the Pretty Good Privacy cryptographic technology, ships with many open source operating systems such as FreeBSD, OpenBSD and many Linux distributions.
The vulnerabilities could pose a threat to the value of digital signatures, Tavis Ormandy of the Gentoo Linux security team wrote in an email interview on Friday. For example, a miscreant could add information to a security alert sent via email or forge the digital signature on software updates, said Ormandy, who discovered both flaws.
This poses a risk to those who use the open source cryptographic technology to authenticate email communications or digitally sign files and, even more so, to the recipients of those messages and users of the files.
Linux and Unix distributors, for example, often use GPG digital signatures in their security advisories so customers can verify the announcement is authentic, Ormandy wrote. The signatures are also used in some software updates these companies put out to ensure nobody has tampered with data, he said.
Ormandy wrote: "GnuPG is used in all sorts of ways to guarantee the authenticity of files and messages. Without the help of GPG, you can bet phoney advisories with advice to download malicious files would be a daily occurrence."
Systems used to distribute software updates that rely on GPG are likely to need fixing. Ormandy wrote: "It is likely that many software update systems - especially on Linux - rely on GPG and will require an update to prevent anyone malicious tampering with software repositories."
Fixes for the flaws are available from the GnuPG team. In addition, those who include the technology in their own products, such as Gentoo and Novell, have been pushing out updates for their products.
The most recent patch was released on Thursday. It was discovered that it is possible to insert data into a digitally signed message, which the system would still verify as authentic, according to a GnuPG security advisory.
Ormandy discovered this latest flaw when further researching an earlier bug, for which a patch was released on 15 February. That earlier flaw could cause automated signature checkers on file downloads to consider a file safe, while the signature was forged, according to a Novell Suse Linux alert.
There have been no reports of attacks that exploit the vulnerabilities. However, users of the vulnerable software should install security updates soon to ensure they are protected.
Joris Evers writes for CNET News.com
Back to Open source Special Report
Web 2.0 prompts love for open source
Database market hits $850m
South Africa plumps for Open Documents
All about interoperability...
Norwegian desktop Linux switch halted
Bergen puts open source plans on ice...
Welsh council embraces open source
Email system for schools to serve up to 40,000...
Mobile Linux movement picks up pace
Challenging the Microsoft and Symbian behemoths...
Stories from around the web...
Q&A: Mark Spencer, CEO of open source VoIP company Digium CNET News.com
The top open source security applications CIO Today
Is open source ERP the best choice for SMBs? Search Enterprise Linux
Open source's lessons from userspace ZDNet UK
Open-source databases find their place in the enterprise Techworld.com
Choosing Desktop Linux
With its 'free' open source status and claims of high security, the appeal of Linux is clear.
Yet recent research from analysts Quocirca reveals the majority of organisations who have looked at the Desktop Linux option are still either at the experimental or limited-deployment stage.
This indicates Linux is no 'magic bullet' for Windows' shortcomings. While a move to Linux might in theory tackle some of the challenges at an operating system level, it is highly likely to create a whole bunch of other problems along the way.
To find out more about Quocirca's findings on Desktop Linux - and request a free copy of their report, click here.
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page