3 ms·
I'm a bit confused. The paper states: "We have disclosed our attack to GnuPG developers under CVE-2014-3591, suggested suitable countermeasures, and worked wit
by clsec 11y ago
I'm a bit confused. The paper states:
"We have disclosed our attack to GnuPG developers under CVE-2014-3591, suggested suitable countermeasures, and worked with the developers to test them. GnuPG 1.4.19 and Libgcrypt 1.6.3 (which underlies GnuPG 2.x), containing these countermeasures and resistant to the key-extraction attack described here, were released concurrently with the first public posting of these results."
Basically that Libcrypt 1.6.3 underlies GnuPG 2.x. But when I check my system:
foo@bar:~$ gpg2 --version
gpg (GnuPG) 2.0.22
libgcrypt 1.5.3
So I'm wondering why GnuPG 2.0.22 isn't using Libgcrypt 1.6.x?
I can see from your reference that I can upgrade to Libgcrypt 1.6.x but that it requires a rebuild of GnuPG, which I'd rather not deal with right now.
- atmosx 11y agoYou sound like if you're going to build the binary manually (using an axe or something). Just compile the latest version for your system. Your distribution's package manager should be up-to-date by now.