A serious flaw in the GnuPG crypto library can be pwned during decryption, potentially resulting in Remote Code Execution (RCE). Patch now! . Bug hunter Tavis Ormandy of Google’s Project Zero just discovered a dangerous bug in the GNU Privacy Guard team’s libgcrypt encryption software. The libgcrypt library is an open-source toolkit that anyone can use, but it’s probably best known as the encryption library used by the GNU Privacy Guard team’s own widely deployed GnuPG software (that’s the package you are using when you run the command gpg or gpg2 ). . An alarming flaw found in OpenSSL's security framework may result in potential exploitation risks. Update immediately!. GnuPG, Remote Code Execution, Critical Threat, Libgcrypt, Encryption. . Brittany Day
Users are being urged to upgrade OpenSSL to prevent eavesdroppers listening to otherwise encrypted connections undermined through the LogJam vulnerability thought to be the NSA's crypto-cracking tool of choice.. OpenSSL maintainers have patched seven vulnerabilities including the LogJam vulnerability (CVE-2015-4000) which allows attackers to trick browsers into considering an insecure encrypted connection as secure. "A vulnerability in the TLS protocol allows a man-in-the-middle attacker to downgrade vulnerable TLS connections using ephemeral Diffie-Hellman key exchange to 512-bit export-grade cryptography," OpenSSL maintainers wrote in an advisory. The link for this article located at The Register UK is no longer available. . The recent update of OpenSSL resolves a total of eight vulnerabilities, among which is the severe DROWN flaw that compromises the integrity of encrypted communications.. OpenSSL Updates, LogJam Vulnerability, TLS Security Patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.