Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

SigSpoof

From Wikipedia, the free encyclopedia
This articlemay be too technical for most readers to understand. Pleasehelp improve it tomake it understandable to non-experts, without removing the technical details.(September 2018) (Learn how and when to remove this message)
Security vulnerabilities that affected GNU Privacy Guard

SigSpoof
CVE identifier(s)CVE-2018-12020
Date discoveredJune 2018; 6 years ago (2018-06)
DiscovererMarcus Brinkmann
Affected softwareGNU Privacy Guard (GnuPG) from v0.2.2 to v2.2.8.

SigSpoof (CVE-2018-12020) is a family ofsecurity vulnerabilities that affected the software packageGNU Privacy Guard ("GnuPG") since version 0.2.2, that was released in 1998.[1] Several other software packages that make use of GnuPG were also affected, such asPass andEnigmail.[2][1]

In un-patched versions of affected software, SigSpoof attacks allowcryptographic signatures to be convincinglyspoofed, under certain circumstances.[1][3][4][2][5] This potentially enables a wide range of subsidiary attacks to succeed.[1][3][4][2][5]

References

[edit]
  1. ^abcdGoodin, Dan (2018-06-14)."Decades-old PGP bug allowed hackers to spoof just about anyone's signature".Ars Technica. Retrieved2018-10-08.
  2. ^abcChirgwin, Richard (2018-06-19)."Pass gets a fail: Simple Password Store suffers GnuPG spoofing bug".The Register. Retrieved2018-10-08.
  3. ^abBöck, Hanno (2018-06-13)."SigSpoof: Signaturen fälschen mit GnuPG".Golem.de. Retrieved2018-10-08.
  4. ^abvon Westernhagen, Olivia (2018-06-14)."Enigmail und GPG Suite: Neue Mail-Plugin-Versionen schließen GnuPG-Lücke".Heise Security. Retrieved2018-10-08.
  5. ^ab"20 Jahre alter Fehler entdeckt: PGP-Signaturen ließen sich einfach fälschen - derStandard.at".Der Standard. 2018-06-18. Retrieved2018-10-08.
Hacking in the 2010s
Major incidents
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
Hacktivism
Groups
Individuals
Majorvulnerabilities
publiclydisclosed
Malware
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019


Stub icon

Thiscomputer security article is astub. You can help Wikipedia byexpanding it.

Retrieved from "https://en.wikipedia.org/w/index.php?title=SigSpoof&oldid=1219321893"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2025 Movatter.jp