A serious flaw in the GnuPG crypto library can be pwned during decryption, potentially resulting in Remote Code Execution (RCE). Patch now! . Bug hunter Tavis Ormandy of Google’s Project Zero just discovered a dangerous bug in the GNU Privacy Guard team’s libgcrypt encryption software. The libgcrypt library is an open-source toolkit that anyone can use, but it’s probably best known as the encryption library used by the GNU Privacy Guard team’s own widely deployed GnuPG software (that’s the package you are using when you run the command gpg or gpg2 ). . An alarming flaw found in OpenSSL's security framework may result in potential exploitation risks. Update immediately!. GnuPG, Remote Code Execution, Critical Threat, Libgcrypt, Encryption. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.