oss-sec mailing list archives
Re: Many vulnerabilities in GnuPG
From: Sam James <sam () gentoo org>
Date: Mon, 29 Dec 2025 20:09:04 +0000
Henrik Ahlgren <pablo () seestieto com> writes:
"Lexi Groves (49016)" <contact () gpg fail> writes:Yes. We found this advice in [The GNU Privacy Handbook, Chapter 1. Getting Started, Making and verifying signatures](https://www.gnupg.org/gph/en/manual/x135.html):I'd just like to point out that the GNU Privacy Handbook (GPH) was published in 1999, and I have not encountered any more recent revisions.
I got this impression but couldn't find anything specifically saying it was archived. I filed a bug earlier and included https://dev.gnupg.org/T7993#210212 for one issue in it, but if it's not been revised since, perhaps it should be archived with a banner on each page or something, as it's readily found via search engines at the moment.
I believe GnuPG did not even support RSA until version 1.0.3 and AES/Rijndael until version 1.0.4, which were released in 2000, meaning the handbook exclusively addresses DSA and ElGamal, making it 25 years out of date.
The GnuPG versions in the output got me suspicious enough ;)
The GnuPG Manual (https://gnupg.org/documentation/manuals/gnupg/) is much more current, but sadly it is not structured as a user guide that would introduce a new user to PGP concepts and best practices, etc.
sam
Current thread:
- Re: Many vulnerabilities in GnuPG, (continued)
- Re: Many vulnerabilities in GnuPG Jacob Bachmeyer (Dec 27)
- Re: Many vulnerabilities in GnuPG Salvatore Bonaccorso (Dec 28)
- Re: Many vulnerabilities in GnuPG Werner Koch (Dec 29)
- Re: Many vulnerabilities in GnuPG Demi Marie Obenour (Dec 29)
- Re: safe use of cleartext signatures? (was: Many vulnerabilities in GnuPG) Jacob Bachmeyer (Dec 30)
- Re: safe use of cleartext signatures? Werner Koch (Dec 30)
- Re: safe use of cleartext signatures? Demi Marie Obenour (Dec 30)
- Re: safe use of cleartext signatures? Werner Koch (Dec 31)
- Re: Many vulnerabilities in GnuPG Jacob Bachmeyer (Dec 27)
- Re: Many vulnerabilities in GnuPG Lexi Groves (49016) (Dec 29)
- Re: Many vulnerabilities in GnuPG Henrik Ahlgren (Dec 29)
- Re: Many vulnerabilities in GnuPG Sam James (Dec 29)
- Re: Many vulnerabilities in GnuPG Jacob Bachmeyer (Dec 30)
- Re: Many vulnerabilities in GnuPG Demi Marie Obenour (Dec 30)
- Re: Many vulnerabilities in GnuPG Sam James (Dec 30)
- Re: Many vulnerabilities in GnuPG Jeffrey Walton (Dec 30)
- Re: Many vulnerabilities in GnuPG Andreas Metzler (Dec 29)
- Re: Many vulnerabilities in GnuPG Peter Gutmann (Dec 29)
- Re: Many vulnerabilities in GnuPG Demi Marie Obenour (Dec 30)
- Re: Many vulnerabilities in GnuPG Peter Gutmann (Dec 30)
