[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2860-1 parcimonie -- information disclosure

ID: oval:org.secpod.oval:def:601214Date: (C)2014-02-19   (M)2022-10-10
Class: PATCHFamily: unix




Holger Levsen discovered that parcimonie, a privacy-friendly helper to refresh a GnuPG keyring, is affected by a design problem that undermines the usefulness of this piece of software in the intended threat model. When using parcimonie with a large keyring , it would always sleep exactly ten minutes between two key fetches. This can probably be used by an adversary who can watch enough key fetches to correlate multiple key fetches with each other, which is what parcimonie aims at protecting against. Smaller keyrings are affected to a smaller degree. This problem is slightly mitigated when using a HKP pool as the configured GnuPG keyserver.

Platform:
Debian 7.0
Product:
parcimonie
Reference:
DSA-2860-1
CVE-2014-1921
CVE    1
CVE-2014-1921
CPE    2
cpe:/a:parcimonie_project:parcimonie
cpe:/o:debian:debian_linux:7.0

© SecPod Technologies