DSA-2860-1 parcimonie -- information disclosureID: oval:org.secpod.oval:def:601214 | Date: (C)2014-02-19 (M)2022-10-10 |
Class: PATCH | Family: unix |
Holger Levsen discovered that parcimonie, a privacy-friendly helper to refresh a GnuPG keyring, is affected by a design problem that undermines the usefulness of this piece of software in the intended threat model. When using parcimonie with a large keyring , it would always sleep exactly ten minutes between two key fetches. This can probably be used by an adversary who can watch enough key fetches to correlate multiple key fetches with each other, which is what parcimonie aims at protecting against. Smaller keyrings are affected to a smaller degree. This problem is slightly mitigated when using a HKP pool as the configured GnuPG keyserver.