March 7, 2007 1:23 PM PST

Bug may expose encrypted e-mail

A problem related to a widely used open-source cryptography technology could let miscreants tamper with digitally signed and encrypted e-mails.

The problem lies in how certain e-mail applications display messages signed using the GNU Privacy Guard, also known as GnuPG and GPG, the GnuPG group said in a security alert Tuesday. It may not be possible to identify which part of a message is actually signed if GPG is not used correctly, it said.

"It is possible to insert additional text before or after a signed, or signed and encrypted, OpenPGP message and make the user believe that this additional text is also covered by the signature," according to the alert.

This poses a risk to those who use the cryptographic technology to authenticate or encrypt e-mail messages. A similar problem occurred last year with the GnuPG technology.

Several open-source e-mail clients are affected by this latest issue, according to security company Core Security Technologies, which discovered the issue. The list of affected applications includes KDE's KMail, Novell's Evolution, Sylpheed, Mutt and GnuMail.org, according to Core. Enigmail, an extension to the Mozilla mail clients, is also vulnerable, the security research company said.

"It is important to note that this is not a cryptographic problem. It affects how information is presented to the user and how third-party applications interact with GnuPG," Core said in an alert.

In addition to adding content to seemingly secure e-mails, attackers can exploit the problem to bypass content-filtering defenses such as antispam mechanisms, Core said.

GnuPG is a free replacement for the Pretty Good Privacy cryptographic technology. An e-mail that uses OpenPGP cryptography can be made up of multiple sections, not all of which need to be signed or encrypted. E-mail programs that do not correctly interpret the message could indicate that a message is fully secure when, in fact, it is not.

"You see the pretty icon telling you that the whole message is encrypted and signed, whereas there is a section of it--text, image, binary, whatever--which isn't," Arrigo Triulzi, a SANS Internet Storm Center staffer, wrote on the organization's blog.

The GnuPG group has issued updates to prevent tampering with signed or encrypted messages, but it notes that individual e-mail applications might need updating as well, to correctly display signed messages after applying the GPG update.

"After applying one of these patches, some vulnerable applications may fail to handle certain messages," the GnuPG alert states. "Fixing the application is required, as there is no way for GnuPG to do it."

Enigmail software has already been updated.

Core also published a work-around to help users detect and prevent exploitation. If a signed message looks suspicious, the validity of the signature can be verified by manually invoking GnuPG from the command line and adding the special option "--status-fd" to gain extra information, Core suggested.

See more CNET content tagged:
Core Security Technologies, cryptography, message, e-mail, open source

Add a Comment (Log in or register) 3 comments
More retards
by bluefoxicy March 8, 2007 12:15 AM PST
Don't read anything from CNet or ZDNet.

May expose ENCRYPTED e-mail? This is a signing flaw, it won't expose the key. It's the same flaw from last year, where you put more text past the signed message body. You can't insert it in the middle of the message even!

If you come across an encrypted message, good for you. You can't read it. This flaw would allow you to... make the message show more text at the end, before or after being decrypted (the encrypted mail looks like a block of junk, then below you see the inserted extra message; decrypted, the block of junk becomes the original message and the inserted message stays).
Reply to this comment
Old news
by Philips March 8, 2007 12:53 AM PST
The issue was beaten before many time. This is not problem with GPG - this is problem with mail relays which try to insert their stuff into mail incorrectly, often resulting in unencryptable mail.

And that's why GPG is lax on when it comes to mails with both unencrypted/unsigned and encrypted/signed parts.

This is not problem of GPG per se - this is problem (again!) of SMTP protocol used to deliver mail.
Reply to this comment
Duh... the writing has been on the wall for some time.
by wbenton March 10, 2007 7:04 AM PST
That said... this isn't news... it's olds.

Get with it people... this is not headline news... it's Old info at best!!!

FWIW
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Overseas, IBM growth consistently modest

    Big Blue's third-quarter revenue growth in Europe, the Middle East, and Africa is shaping up to reflect the "moderate IT-spending environment" it earlier characterized.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • The Digital Home

    It's time for Sony to downsize

    Don Reisinger thinks it's time for Sony to downsize. But Sony's success may dictate otherwise.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Zillow, newspaper consortium launch ad network

    Real-estate site Zillow.com and a newspaper consortium expand their 2007 partnership, giving local advertisers exposure on Zillow and national advertisers exposure on newspaper sites.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Say Where brings voice recognition to iPhone apps

    Forthcoming iPhone app from Dial Directions aims to give users a way to get information from sites like Yelp, MapQuest and others by speaking instead of typing.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Webware

    TechCrunch50: Ten to watch

    Notes from the pitch book: Rafe's top 10

  • Green Tech

    TI does energy efficiency on a chip

    Its line of Piccolo microcontrollers can reduce power consumption significantly of home appliances, hybrid cars, LED lighting, and even solar panels.