ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Bug may pose risk to encrypted email

Joris Evers CNET News.com

Published: 08 Mar 2007 10:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A problem related to a widely used open-source cryptography technology could let miscreants tamper with digitally signed and encrypted emails.

The problem lies in how certain email applications display messages signed using the GNU Privacy Guard, also known as GnuPG and GPG, the GnuPG group said in a security alert on Tuesday. It may not be possible to identify which part of a message is actually signed if GPG is not used correctly, it said.

"It is possible to insert additional text before or after a signed, or signed and encrypted, OpenPGP message and make the user believe that this additional text is also covered by the signature," according to the alert.

This poses a risk to those who use the cryptographic technology to authenticate or encrypt email messages. A similar problem occurred last year with the GnuPG technology.

Several open-source email clients are affected by this latest issue, according to security company Core Security Technologies, which discovered the problem. The list of affected applications includes KDE's KMail, Novell's Evolution, Sylpheed, Mutt and GnuMail.org, according to Core. Enigmail, an extension to the Mozilla mail clients, is also vulnerable, the security research company said.

"It is important to note that this is not a cryptographic problem. It affects how information is presented to the user and how third-party applications interact with GnuPG," Core said in an alert.

In addition to adding content to seemingly secure emails, attackers can exploit the problem to bypass content-filtering defences such as antispam mechanisms, Core said.

GnuPG is a free replacement for the Pretty Good Privacy cryptographic technology. An email that uses OpenPGP cryptography can be made up of multiple sections, not all of which need to be signed or encrypted. Email programs that do not correctly interpret the message could indicate that a message is fully secure when, in fact, it is not.

"You see the pretty icon telling you that the whole message is encrypted and signed, whereas there is a section of it &,dash; text, image, binary, whatever — which isn't," Arrigo Triulzi, a SANS Internet Storm Center staffer, wrote on the organisation's blog.

The GnuPG group has issued updates to prevent tampering with signed or encrypted messages, but it notes that individual email applications might need updating as well, to correctly display signed messages after applying the GPG update.

"After applying one of these patches, some vulnerable applications may fail to handle certain messages," the GnuPG alert states. "Fixing the application is required, as there is no way for GnuPG to do it."

Enigmail software has already been updated.

Core also published a workaround to help users detect and prevent exploitation. If a signed message looks suspicious, the validity of the signature can be verified by manually invoking GnuPG from the command line and adding the special option "--status-fd" to gain extra information, Core suggested.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
10 out of 10 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

5 comments