Page MenuHome GnuPG
Feed Advanced Search

Jun 14 2018

werner added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

Although "certificate" is used for OpenPGP revocations, it is technically a signature.

Jun 14 2018, 2:36 PM · gnupg, Bug Report
werner committed rD73c278e7b09f: web: typo fix (authored by werner).
web: typo fix
Jun 14 2018, 10:26 AM
werner triaged T4022: too-large User ID packets result in dropping an entire certificate as High priority.
Jun 14 2018, 8:07 AM · gnupg, Bug Report

Jun 13 2018

werner committed rD969e129dbd6b: web: Release info for libgcrypt 1.8.3 (authored by werner).
web: Release info for libgcrypt 1.8.3
Jun 13 2018, 6:38 PM
werner closed T4011: CVE-2018-0495 as Resolved.
Jun 13 2018, 6:33 PM · CVE, libgcrypt
werner added a comment to T4011: CVE-2018-0495.

Here is our announcement: https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000426.html

Jun 13 2018, 6:32 PM · CVE, libgcrypt
werner added a comment to T4011: CVE-2018-0495.

https://www.nccgroup.trust/us/our-research/technical-advisory-return-of-the-hidden-number-problem/

Jun 13 2018, 5:40 PM · CVE, libgcrypt
werner committed rP779b8e6df7d2: core: Add info about tty mode etc to 'getinfo ttyinfo' (authored by werner).
core: Add info about tty mode etc to 'getinfo ttyinfo'
Jun 13 2018, 5:18 PM
werner changed the visibility for T4011: CVE-2018-0495.
Jun 13 2018, 12:40 PM · CVE, libgcrypt
werner added a comment to T4011: CVE-2018-0495.

A new installer for GnuPG with Libgcrypt 1.8.3 is now available.

Jun 13 2018, 12:38 PM · CVE, libgcrypt
werner committed rD9689413979fa: swdb: New gnupg w32 installer with latest Libgcrypt (authored by werner).
swdb: New gnupg w32 installer with latest Libgcrypt
Jun 13 2018, 12:25 PM
werner added a comment to T4011: CVE-2018-0495.

Releases are now available. Next task is to build a new GnuPG Windows installer.

Jun 13 2018, 10:40 AM · CVE, libgcrypt
werner closed T4016: Libgcrypt release 1.8.3 as Resolved.

1.8.3 and 1.7.10 are now released. Announcement will follow later the day.

Jun 13 2018, 10:39 AM · Release Info, CVE, libgcrypt
werner closed T4016: Libgcrypt release 1.8.3, a subtask of T4011: CVE-2018-0495, as Resolved.
Jun 13 2018, 10:39 AM · CVE, libgcrypt
werner committed rC0d51ea9b88b6: Add NEWS from the 1.8 and 1.7 branches. (authored by werner).
Add NEWS from the 1.8 and 1.7 branches.
Jun 13 2018, 10:37 AM
werner committed rC2ace21b1a8e4: Post release updates. (authored by werner).
Post release updates.
Jun 13 2018, 10:25 AM
werner committed rCff8f7e53ce6b: Release 1.7.10 (authored by werner).
Release 1.7.10
Jun 13 2018, 10:25 AM
werner committed rC3caf35a49cb6: Fix incorrect counter overflow handling for GCM (authored by jukivili).
Fix incorrect counter overflow handling for GCM
Jun 13 2018, 10:17 AM
werner committed rC6dd0cf0744db: ecc: Improve gcry_mpi_ec_curve_point (authored by werner).
ecc: Improve gcry_mpi_ec_curve_point
Jun 13 2018, 10:17 AM
werner committed rC3600e1224f6c: mpi: New internal function _gcry_mpi_cmpabs. (authored by werner).
mpi: New internal function _gcry_mpi_cmpabs.
Jun 13 2018, 10:17 AM
werner committed rC528a06b48389: AES-KW: fix in-place encryption (authored by smueller_chronox.de).
AES-KW: fix in-place encryption
Jun 13 2018, 10:17 AM
werner committed rD823e9076f87a: swdb: Libgcrypt 1.8.3 (authored by werner).
swdb: Libgcrypt 1.8.3
Jun 13 2018, 10:06 AM
werner committed rC6ca6344429e5: Post release updates (authored by werner).
Post release updates
Jun 13 2018, 10:01 AM
werner committed rC5600d2d6b236: Release 1.8.3 (authored by werner).
Release 1.8.3
Jun 13 2018, 10:01 AM
werner updated the task description for T4016: Libgcrypt release 1.8.3.
Jun 13 2018, 8:07 AM · Release Info, CVE, libgcrypt
werner added a comment to T4016: Libgcrypt release 1.8.3.

1.8.3 has not yet been released and thus there is no NEWS entries and there can't be a 1.8.3 tag. You are right that the README still says 1.7. I'll fix that for 1.8.3. Why do you think maintenance of 1.7 stopped; the AUTHORS file and the new EOL statements on the download page say that we are going to maintain it until 2019-06-30.

Jun 13 2018, 8:06 AM · Release Info, CVE, libgcrypt
werner added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

What about another record type for standalone revocations, something line "rev0" or "revx"? This would solve the problem on how to distinguish merged revocation signatures (ie with a preceding "pub") from standalone revocations.

Jun 13 2018, 7:58 AM · gnupg, Bug Report

Jun 12 2018

werner committed rGcb52eb76b3ba: Some preparations to eventuallt use gpgrt_argparse. (authored by werner).
Some preparations to eventuallt use gpgrt_argparse.
Jun 12 2018, 4:13 PM
werner committed rG440472663d60: Require libgpg-error 1.29 and remove internal logging functions. (authored by werner).
Require libgpg-error 1.29 and remove internal logging functions.
Jun 12 2018, 1:45 PM
werner updated subscribers of T4011: CVE-2018-0495.

Publication is planned for the 13th, 1500Z

Jun 12 2018, 1:12 PM · CVE, libgcrypt
werner added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

As long as we don't check the signature we don't need the pubkey. That would make it actually easier becuase we have only one case and not 3 or more (bad signature, no pubkey, etc).

Jun 12 2018, 1:10 PM · gnupg, Bug Report
werner closed T4019: --export-filter drop-subkey filter type should have usage option property as Resolved.
Jun 12 2018, 9:09 AM · gnupg, Feature Request
werner closed T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`) as Resolved.
Jun 12 2018, 9:09 AM · gnupg, Bug Report
werner committed rGfe621cc64b13: gpg: Do not import revocations with --show-keys. (authored by werner).
gpg: Do not import revocations with --show-keys.
Jun 12 2018, 9:06 AM
werner committed rGe8f439e05474: gpg: Do not import revocations with --show-keys. (authored by werner).
gpg: Do not import revocations with --show-keys.
Jun 12 2018, 9:05 AM
werner committed rG86b64876bef0: gpg: Add new usage option for drop-subkey filters. (authored by dkg).
gpg: Add new usage option for drop-subkey filters.
Jun 12 2018, 9:05 AM
werner claimed T4018: gpg --with-colons --show-keys does not show revocation certificates.

That will be a bit of work. We can't list a standalone key yet because the the key listing code expects a public or secret key as first packet. Further it would be advisable to insert a dummy "pub" key record before the "rev" record because the advise as always been to use "pub" or "sec" as start of a key keyblock.

Jun 12 2018, 9:02 AM · gnupg, Bug Report
werner added projects to T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`): gnupg, backport.

Thanks for reporting and your patch. However, I used a different way to solve this bug.

Jun 12 2018, 8:46 AM · gnupg, Bug Report
werner triaged T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`) as High priority.
Jun 12 2018, 8:24 AM · gnupg, Bug Report
werner claimed T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`).
Jun 12 2018, 8:24 AM · gnupg, Bug Report
werner triaged T4018: gpg --with-colons --show-keys does not show revocation certificates as High priority.
Jun 12 2018, 8:22 AM · gnupg, Bug Report
werner triaged T4019: --export-filter drop-subkey filter type should have usage option property as Normal priority.

Thanks. Pushed to master. I think it should also go into 2.2.

Jun 12 2018, 8:21 AM · gnupg, Feature Request
werner committed rG2ddfb5bef920: gpg: Add new usage option for drop-subkey filters. (authored by dkg).
gpg: Add new usage option for drop-subkey filters.
Jun 12 2018, 8:19 AM

Jun 11 2018

werner committed rC846f8fe8b3be: ecc: Improve gcry_mpi_ec_curve_point (authored by werner).
ecc: Improve gcry_mpi_ec_curve_point
Jun 11 2018, 7:19 PM
werner committed rC54620a27f450: mpi: New internal function _gcry_mpi_cmpabs. (authored by werner).
mpi: New internal function _gcry_mpi_cmpabs.
Jun 11 2018, 7:19 PM
werner added a comment to T3986: GpgOL: Mitigate manipulations of encrypted S/MIME mails.

Thanks for the writeup. Maybe this could be the base for a gnupg.org/blog article.

Jun 11 2018, 6:56 PM · gpg4win, gpgol
werner committed rD51549ca5dbdc: web: Announce 1.4.23 (authored by werner).
web: Announce 1.4.23
Jun 11 2018, 1:31 PM
werner closed T4012: Diagnostic is shown with the original filename not being sanitized. as Resolved.
Jun 11 2018, 11:23 AM · gnupg, CVE, Bug Report
werner renamed T4012: Diagnostic is shown with the original filename not being sanitized. from Diagnostic is shown with the original filename not beeing sanitized. to Diagnostic is shown with the original filename not being sanitized..
Jun 11 2018, 11:23 AM · gnupg, CVE, Bug Report
werner closed T4015: Release 1.4.23, a subtask of T4012: Diagnostic is shown with the original filename not being sanitized., as Resolved.
Jun 11 2018, 11:23 AM · gnupg, CVE, Bug Report
werner closed T4015: Release 1.4.23 as Resolved.
Jun 11 2018, 11:23 AM · Release Info, gnupg (gpg14), CVE
werner committed rD71724d3c3baf: swdb: Release of Gnupg 1.4.23 (authored by werner).
swdb: Release of Gnupg 1.4.23
Jun 11 2018, 11:16 AM
werner committed rGf32dbf396ae7: Post release updates (authored by werner).
Post release updates
Jun 11 2018, 11:10 AM
werner committed rG8ae6a246bef5: Release 1.4.23 (authored by werner).
Release 1.4.23
Jun 11 2018, 11:10 AM
werner committed rGdd6192bfea80: po: Auto update (authored by werner).
po: Auto update
Jun 11 2018, 11:10 AM
werner added a project to T4015: Release 1.4.23: Release Info.
Jun 11 2018, 9:59 AM · Release Info, gnupg (gpg14), CVE
werner added a project to T4016: Libgcrypt release 1.8.3: Release Info.
Jun 11 2018, 9:58 AM · Release Info, CVE, libgcrypt
werner set the color for Release Info to Pink.
Jun 11 2018, 9:58 AM
werner changed the edit policy for T4016: Libgcrypt release 1.8.3.
Jun 11 2018, 9:55 AM · Release Info, CVE, libgcrypt
werner created T4015: Release 1.4.23.
Jun 11 2018, 9:52 AM · Release Info, gnupg (gpg14), CVE
werner renamed T4012: Diagnostic is shown with the original filename not being sanitized. from Diagnostic with original filename is not sanitized. to Diagnostic is shown with the original filename not beeing sanitized..
Jun 11 2018, 9:50 AM · gnupg, CVE, Bug Report
werner committed rG615b9d1fb779: doc: Include release info from 2.2.8 (authored by werner).
doc: Include release info from 2.2.8
Jun 11 2018, 9:04 AM
werner committed rGdc96fd883571: doc: Mention new command --show-keys in the 2.2.7 NEWS. (authored by werner).
doc: Mention new command --show-keys in the 2.2.7 NEWS.
Jun 11 2018, 9:04 AM
werner committed rGcbb84b336126: gpg: Set some list options with --show-keys (authored by werner).
gpg: Set some list options with --show-keys
Jun 11 2018, 8:58 AM
werner committed rGd2bc66f241a6: gpg: Set some list options with --show-keys (authored by werner).
gpg: Set some list options with --show-keys
Jun 11 2018, 8:57 AM

Jun 10 2018

werner committed rD031285b8ea7d: donations: Use a tag cloud for all years (authored by werner).
donations: Use a tag cloud for all years
Jun 10 2018, 7:31 PM
werner committed rD1cbec4b8d0cb: donations: Fix a link (authored by werner).
donations: Fix a link
Jun 10 2018, 6:00 PM
werner committed rDd4b98f9c0c55: donations: Try a tag cloud list for the 2018 donors. (authored by werner).
donations: Try a tag cloud list for the 2018 donors.
Jun 10 2018, 6:00 PM
werner committed rDe0195fc71ef5: donations: Add a remark to the auto created list (authored by werner).
donations: Add a remark to the auto created list
Jun 10 2018, 5:55 PM
werner committed rD34aadf0da76b: donations: Add stats for 2017 (authored by werner).
donations: Add stats for 2017
Jun 10 2018, 5:51 PM
werner committed rD591b60c8a8fb: donations: Add monthly statistics (authored by werner).
donations: Add monthly statistics
Jun 10 2018, 5:10 PM

Jun 9 2018

werner committed rDbaab91c94915: web: news was missing the setup file (authored by werner).
web: news was missing the setup file
Jun 9 2018, 2:13 PM
werner committed rDc51957c87d6e: web: Add links to CVE ids. (authored by werner).
web: Add links to CVE ids.
Jun 9 2018, 12:56 PM
werner committed rDe709c9306139: web: New macro CVE and fix for latest CVE link. (authored by werner).
web: New macro CVE and fix for latest CVE link.
Jun 9 2018, 12:43 PM
werner committed rD680e8aa513ce: web: Fix URL typo and add a missing OID. (authored by werner).
web: Fix URL typo and add a missing OID.
Jun 9 2018, 11:50 AM
werner removed a project from T4012: Diagnostic is shown with the original filename not being sanitized.: backport.
Jun 9 2018, 11:46 AM · gnupg, CVE, Bug Report
werner added a project to T4012: Diagnostic is shown with the original filename not being sanitized.: backport.
Jun 9 2018, 11:46 AM · gnupg, CVE, Bug Report
werner lowered the priority of T4012: Diagnostic is shown with the original filename not being sanitized. from Unbreak Now! to High.
Jun 9 2018, 11:45 AM · gnupg, CVE, Bug Report
werner added a comment to T3844: Able to certify public keys without a certify key present when using smartcard..

So we had two releases with the fist. Can we set this bug to resolved?

Jun 9 2018, 11:35 AM · gnupg (gpg22), Bug Report

Jun 8 2018

werner triaged T4013: Certificate requests generated from Ed25519 keys are not compliant with draft-ietf-curdle-pkix as Normal priority.

I was not aware that you could do this at all. You are right in that to start supporting this we first need to update libksba.

Jun 8 2018, 10:15 PM · S/MIME, Feature Request, libksba
werner added a comment to T4012: Diagnostic is shown with the original filename not being sanitized..

Unfortunately 2.2.8 does not build with older libgpg-error versions. Commit rG18274db32b5dea7fe8db67043a787578c975de4d should fix this.

Jun 8 2018, 10:11 PM · gnupg, CVE, Bug Report
werner committed rG18274db32b5d: gpg: Allow building with older libgpg-error. (authored by werner).
gpg: Allow building with older libgpg-error.
Jun 8 2018, 10:09 PM
werner committed rDd1df251db10b: web: News about GnuPG 2.2.8 (authored by werner).
web: News about GnuPG 2.2.8
Jun 8 2018, 4:07 PM
werner added a comment to T4012: Diagnostic is shown with the original filename not being sanitized..

2.2.8. with a fix has been released. Announcement

Jun 8 2018, 3:54 PM · gnupg, CVE, Bug Report
werner committed rD093143fe54d7: swdb: Release GnuPG 2.2.8 (authored by werner).
swdb: Release GnuPG 2.2.8
Jun 8 2018, 1:06 PM
werner committed rGe9667dd20a3a: Post release updates (authored by werner).
Post release updates
Jun 8 2018, 12:58 PM
werner committed rGcd9aaa786295: Release 2.2.8 (authored by werner).
Release 2.2.8
Jun 8 2018, 12:58 PM
werner committed rG8e589300e371: po: Auto update (authored by werner).
po: Auto update
Jun 8 2018, 12:58 PM
werner committed rGea36e637224f: po: Update German translation (authored by werner).
po: Update German translation
Jun 8 2018, 12:58 PM
werner committed rG77ab99f80a5b: po: Update Russian translation. (authored by Ineiev <ineiev@gnu.org>).
po: Update Russian translation.
Jun 8 2018, 12:58 PM
werner edited projects for T4012: Diagnostic is shown with the original filename not being sanitized., added: gnupg; removed gnupg (gpg14).

[Better use the gnupg tag. Specific versions end up on the workboard and there may only be one.]

Jun 8 2018, 12:10 PM · gnupg, CVE, Bug Report
werner closed T4000: GnuPG does not check encrypted messages for well-formed composition as Resolved.
Jun 8 2018, 11:16 AM · gnupg (gpg22), Bug Report
werner edited projects for T4012: Diagnostic is shown with the original filename not being sanitized., added: CVE, gnupg (gpg14); removed gnupg (gpg22).

@dkg can you please take this up with Debian and other distros? See the commit for a brief description.

Jun 8 2018, 11:12 AM · gnupg, CVE, Bug Report
werner changed the status of T4012: Diagnostic is shown with the original filename not being sanitized. from Open to Testing.

Fixed in 1.4, 2.2 and master. New releases will be done soon. Note that there is no need for a new gpg4win release because GPGME is not affected.

Jun 8 2018, 11:09 AM · gnupg, CVE, Bug Report
werner committed rG2326851c6079: gpg: Sanitize diagnostic with the original file name. (authored by werner).
gpg: Sanitize diagnostic with the original file name.
Jun 8 2018, 11:01 AM
werner committed rG210e402acd3e: gpg: Sanitize diagnostic with the original file name. (authored by werner).
gpg: Sanitize diagnostic with the original file name.
Jun 8 2018, 10:54 AM
werner committed rG13f135c7a252: gpg: Sanitize diagnostic with the original file name. (authored by werner).
gpg: Sanitize diagnostic with the original file name.
Jun 8 2018, 10:54 AM
werner created T4012: Diagnostic is shown with the original filename not being sanitized..
Jun 8 2018, 10:52 AM · gnupg, CVE, Bug Report
werner closed T3942: Can't unregister a non-existent private key as Resolved.

Okay. Thanks for looking into this.

Jun 8 2018, 10:19 AM · gnupg (gpg22), Bug Report
werner edited Description on CVE.
Jun 8 2018, 10:18 AM