Hello GnuPG upstream,
based on http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=712744 looks
currently gpg-agent tool does not have core dumps disabled (like for example
ssh-agent does).
While this would not be a security flaw, but looks like a proper candidate for
enhancement.
Can you implement / apply the call to prctl(PR_SET_DUMPABLE, 0); for gpg-agent
in future gnupg2 versions? (possibly together with updating gpg-agent CLI -
adding option that would act as switch to specify, when dumping of core files
should be enabled / is desired, and documenting that option in the manual page)
Thank you && Regards, Jan.
Jan iankko Lieskovsky / Red Hat Security Response Team