openbsd-ports/security/gnupg/patches
reinhard 36bdf033ff SECURITY UPDATE (Klima-Rosa attack)
patch from:
Florian Weimer <Florian.Weimer@RUS.UNI-STUTTGART.DE>
# http://cert.uni-stuttgart.de/files/fw/gnupg-klima-rosa.diff
# http://cert.uni-stuttgart.de/files/fw/gnupg-klima-rosa.diff.asc

It introduces additional consistency checks, as suggested by the
authors of the paper.  The checks are slightly different, but they
make the two additional attacks infeasible, I think.  In the future,
it might be a good idea to add a check the generated signature for
validity, this will detect bugs in the MPI implementation which could
result in a revealed secret key, too.


ok markus@
2001-03-23 13:10:20 +00:00
..
patch-cipher_rsa_c SECURITY UPDATE (Klima-Rosa attack) 2001-03-23 13:10:20 +00:00
patch-configure_in o) minor fix for one of the MASTER_SITES; Pete Fritchman <petef@databits.net> 2001-03-03 17:17:28 +00:00
patch-doc_Makefile.in security update, since 1.0.3 does not detect modifications of files with multiple signatures 2000-10-30 12:52:32 +00:00
patch-g10_mainproc.c Security update, from the original patch: 2000-12-23 15:20:59 +00:00
patch-g10_misc.c security update, since 1.0.3 does not detect modifications of files with multiple signatures 2000-10-30 12:52:32 +00:00
patch-g10_openfile.c Security update, from the original patch: 2000-12-23 15:20:59 +00:00
patch-g10_plaintext.c Security update, from the original patch: 2000-12-23 15:20:59 +00:00