Tool Release (GNU Privacy Guard), compliant with OpenPGP standards () and S/MIME, providing utilities for data encryption, working with digital signatures, key management, and access to public key repositories. The new version addresses a critical vulnerability (), which manifests starting from version 2.2.21 and is exploitable when importing specially crafted OpenPGP keys.
Importing a key with a specially crafted large list of AEAD algorithms can lead to array overflow and crash or undefined behavior. It is noted that creating an exploit that leads to something other than a crash is a complex task, but such a possibility cannot be ruled out. The main difficulty in developing an exploit is that the attacker can control only every second byte of the sequence, while the first byte always takes the value 0x04. Software distribution systems with digital key verification are safe, as they use a predefined list of keys.
Source: opennet.ru
