oss-sec mailing list archives
Re: Many vulnerabilities in GnuPG
From: Sam James <sam () gentoo org>
Date: Sun, 28 Dec 2025 11:38:29 +0000
Solar Designer <solar () openwall com> writes:
On Sat, Dec 27, 2025 at 07:29:53PM -0500, Demi Marie Obenour wrote:https://gpg.fail lists many vulnerabilities in GnuPG, one of which allows remote code execution. All are zero-days to the best of my knowledge.Thanks. I wish this were brought in here by the researchers, but since it was not and since we require actual content here (not just links),
Indeed. I'll note that several of the vulnerability pages (say https://gpg.fail/sha1) have:
Upcoming Timeline: [...] 21.12.2025: Disclosure of this report on https://seclists.org/fulldisclosure/
But I've not been able to find such a report there either.
Attachment:
signature.asc
Description:
Current thread:
- Re: safe use of cleartext signatures?, (continued)
- Re: safe use of cleartext signatures? Werner Koch (Dec 30)
- Re: safe use of cleartext signatures? Demi Marie Obenour (Dec 30)
- Re: safe use of cleartext signatures? Werner Koch (Dec 31)
- Re: Many vulnerabilities in GnuPG Lexi Groves (49016) (Dec 29)
- Re: Many vulnerabilities in GnuPG Henrik Ahlgren (Dec 29)
- Re: Many vulnerabilities in GnuPG Sam James (Dec 29)
- Re: Many vulnerabilities in GnuPG Jacob Bachmeyer (Dec 30)
- Re: Many vulnerabilities in GnuPG Demi Marie Obenour (Dec 30)
- Re: Many vulnerabilities in GnuPG Sam James (Dec 30)
- Re: Many vulnerabilities in GnuPG Jeffrey Walton (Dec 30)
- Re: Many vulnerabilities in GnuPG Andreas Metzler (Dec 29)
- Re: Many vulnerabilities in GnuPG Peter Gutmann (Dec 29)
- Re: Many vulnerabilities in GnuPG Demi Marie Obenour (Dec 30)
- Re: Many vulnerabilities in GnuPG Peter Gutmann (Dec 30)
- Re: Many vulnerabilities in GnuPG Henrik Ahlgren (Dec 30)
- Re: Many vulnerabilities in GnuPG Collin Funk (Dec 30)
- Re: Many vulnerabilities in GnuPG Peter Gutmann (Dec 31)
