oss-sec mailing list archives
Re: safe use of cleartext signatures? (was: Many vulnerabilities in GnuPG)
From: Jacob Bachmeyer <jcb62281 () gmail com>
Date: Tue, 30 Dec 2025 00:34:04 -0600
On 12/29/25 03:51, Werner Koch wrote:
Hi! Jacob was so kind to comment on the reported bugs. I agree with most of his comments. [...]
Thank you.
[...] At that time I also drafted an article to explain the well known prblem of hard-to-correct-use of cleartext signatures including a bit of history: https://gnupg.org/blog/20251226-cleartext-signatures.html
This is also the most important point to me, because cleartext signatures have their uses, for example, signing a list of file digests, which is also the use case attacked in item 10.
Is there a safe (but presumably less convenient) way to use cleartext signatures, perhaps by strictly validating the overall message structure, or is this basically an unfixable problem? Could GPG perform such validation steps and emit a warning if a clearsigned message does not strictly conform?
-- Jacob
Current thread:
- Many vulnerabilities in GnuPG Demi Marie Obenour (Dec 27)
- Re: Many vulnerabilities in GnuPG Solar Designer (Dec 27)
- Re: Many vulnerabilities in GnuPG Solar Designer (Dec 27)
- Re: Many vulnerabilities in GnuPG Jacob Bachmeyer (Dec 27)
- Re: Many vulnerabilities in GnuPG Salvatore Bonaccorso (Dec 28)
- Re: Many vulnerabilities in GnuPG Werner Koch (Dec 29)
- Re: Many vulnerabilities in GnuPG Demi Marie Obenour (Dec 29)
- Re: safe use of cleartext signatures? (was: Many vulnerabilities in GnuPG) Jacob Bachmeyer (Dec 30)
- Re: safe use of cleartext signatures? Werner Koch (Dec 30)
- Re: safe use of cleartext signatures? Demi Marie Obenour (Dec 30)
- Re: safe use of cleartext signatures? Werner Koch (Dec 31)
- Re: Many vulnerabilities in GnuPG Solar Designer (Dec 27)
- Re: Many vulnerabilities in GnuPG Lexi Groves (49016) (Dec 29)
- Re: Many vulnerabilities in GnuPG Henrik Ahlgren (Dec 29)
- Re: Many vulnerabilities in GnuPG Sam James (Dec 29)
- Re: Many vulnerabilities in GnuPG Jacob Bachmeyer (Dec 30)
- Re: Many vulnerabilities in GnuPG Demi Marie Obenour (Dec 30)
- Re: Many vulnerabilities in GnuPG Sam James (Dec 30)
- Re: Many vulnerabilities in GnuPG Jeffrey Walton (Dec 30)
