oss-sec mailing list archives
Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG
From: Peter van Dijk <peter.van.dijk () powerdns com>
Date: Mon, 04 Jul 2022 15:15:40 +0200
On Mon, 2022-07-04 at 14:58 +0200, Jens-Wolfhard Schicke-Uffmann wrote:
Hi, On Mon, Jul 04, 2022 at 02:15:45PM +0200, Peter van Dijk wrote:On 04/07/2022 07:31 Demi Marie Obenour <demi () invisiblethingslab com> wrote: Signature (of /dev/null) that triggers this bug is attached, along with the corresponding public key.This is insane. You can't send weaponised exploits that crash email clients to public mailing lists. Please do not do this again.What email client would that be specifically? Because at least on my end, nothing nefarious happened. GPG was called on the outermost layer of signature and verified the email in entirety (and did so quickly).
GNOME Evolution (Debian's version 3.38.3-1) hangs (interruptibly, by navigating to another message) when trying to open the message. It hangs completely (eventually I used the Force Quit that GNOME offered me) when trying to reply to it. Kind regards, -- Peter van Dijk PowerDNS.COM BV - https://www.powerdns.com/
Current thread:
- Denial of service in GnuPG Demi Marie Obenour (Jul 04)
- DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Peter van Dijk (Jul 04)
- Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Jens-Wolfhard Schicke-Uffmann (Jul 04)
- Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Peter van Dijk (Jul 04)
- Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Kurt H Maier (Jul 05)
- Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Jakub Wilk (Jul 04)
- Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Tavis Ormandy (Jul 06)
- Re: Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Demi Marie Obenour (Jul 06)
- Re: Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Alexander Burke (Jul 06)
- Re: Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Solar Designer (Jul 06)
- Re: Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Demi Marie Obenour (Jul 06)
- Re: Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Solar Designer (Jul 06)
- Re: Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Grant Taylor (Jul 06)
- Re: Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Demi Marie Obenour (Jul 06)
- Re: DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Jens-Wolfhard Schicke-Uffmann (Jul 04)
- DO NOT OPEN PREVIOUS MAIL Re: [oss-security] Denial of service in GnuPG Peter van Dijk (Jul 04)