请输入您要查询的百科知识:

 

词条 SigSpoof
释义

  1. References

{{short description|Security vulnerabilities that affected GNU Privacy Guard}}{{Technical|date=September 2018}}SigSpoof is a family of security vulnerabilities that affected the software package GNU Privacy Guard ("GnuPG") since version 0.2.2, that was released in 1998. Several other software packages that make use of GnuPG were also affected, such as Pass and Enigmail.[2]

In un-patched versions of affected software, SigSpoof attacks allow cryptographic signatures to be convincingly spoofed, under certain circumstances.[5][6][2][8] This potentially enables a wide range of subsidiary attacks to succeed.[5][6][2][8]

According to Marcus Brinkmann, who discovered the SigSpoof vulnerabilities in June 2018, their existence, and the fact that they were present "in the wild" for so long, throws into question the integrity of past emails, "backups, software updates, ... and source code in version control systems like Git."

References

1. ^{{cite web|url=https://www.golem.de/news/sigspoof-signaturen-faelschen-mit-gnupg-1806-134940.html|title=SigSpoof: Signaturen fälschen mit GnuPG|website=Golem.de|last=Böck|first=Hanno|date=2018-06-13|accessdate=2018-10-08}}
2. ^{{cite web|url=https://www.heise.de/security/meldung/Enigmail-und-GPG-Suite-Neue-Mail-Plugin-Versionen-schliessen-GnuPG-Luecke-4078685.html|title=Enigmail und GPG Suite: Neue Mail-Plugin-Versionen schließen GnuPG-Lücke|last=von Westernhagen|first=Olivia|website=Heise Security|accessdate=2018-10-08}}
3. ^{{cite web|url=https://www.theregister.co.uk/2018/06/19/gnupg_popped_again_in_pass/|title=Pass gets a fail: Simple Password Store suffers GnuPG spoofing bug|website=The Register|last=Chirgwin|first=Richard|date=2018-06-19|accessdate=2018-10-08}}
4. ^{{cite web|url=https://derstandard.at/2000081781101/20-Jahre-alter-Fehler-entdeckt-PGP-Signaturen-liessen-sich-einfach|title=20 Jahre alter Fehler entdeckt: PGP-Signaturen ließen sich einfach fälschen - derStandard.at|website=Der Standard|date=2018-06-18|accessdate=2018-10-08}}
[1][2][3][4]
}}{{Hacking in the 2010s}}{{computer-security-stub}}

2 : Vulnerability|Computer security exploits

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/9/22 4:03:25