Decades-old PGP bug allowed hackers to spoof just about anyone’s signature

General News

Summary

For their entire existence, some of the worlds most widely used email encryption tools have been vulnerable to hacks that allowed attackers to spoof the digital signature of just about any person with a public key, a researcher said Wednesday. The flaw, indexed as CVE-2018-12020, means that decades worth of email messages many people relied on for sensitive business or security matters may have in fact been spoofs. "The vulnerability in GnuPG goes deep and has the potential to affect a large part of our core infrastructure," Marcus Brinkmann, the software developer who discovered SigSpoof, wrote in an advisory published Wednesday. Once verbose is enabled, Brinkmanns post includes three separate proof-of-concept spoofing attacks that work against the previously mentioned tools and possibly many others. Separately, Brinkmann reported two SigSpoof-related vulnerabilities in Enigmail and the Simple Password Store that also made it possible to spoof digital signatures in some cases.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
Developer Tools DevOps Software SaaS

Linked Companies

Enigmai
up to $1M
GitHub, Inc.
$1M to $5M
GPG Tools GmbH
up to $1M