• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Google Discloses Severe Bug in Libgcrypt Encryption Library—Impacting Many Projects

You are here: Home / General Cyber Security News / Google Discloses Severe Bug in Libgcrypt Encryption Library—Impacting Many Projects

A “intense” vulnerability in GNU Privacy Guard (GnuPG)’s Libgcrypt encryption computer software could have permitted an attacker to publish arbitrary knowledge to the concentrate on machine, probably main to distant code execution.

The flaw, which impacts variation 1.9. of libgcrypt, was found on January 28 by Tavis Ormandy of Venture Zero, a security research unit inside Google dedicated to discovering zero-working day bugs in hardware and software program systems.

✔ Approved Seller by TheCyberSecurity From Our Partners
F Secure Freedome Vpn 2021

Protect your online privacy and internet browsing via F-Secure Freedome VPN. F-Secure has proven to be a trustworthy company but not being connected to any government. F-Secure Freedome VPN encryptes all your connections to the internet in addition it hides your real IP address so no one will know from which location you are browsing the web. F-Secure Freedome VPN is Netflix and Amazon Prime friendly which means you can easily view the movies and series that are meant for Amercian viewers.

Get F-Secure Freedome VPN with 50% discount from our partner: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


No other versions of Libgcrypt are influenced by the vulnerability.

“There is a heap buffer overflow in libgcrypt due to an incorrect assumption in the block buffer management code,” Ormandy claimed. “Just decrypting some facts can overflow a heap buffer with attacker controlled info, no verification or signature is validated in advance of the vulnerability occurs.”

password auditor

GnuPG dealt with the weak spot almost promptly inside of a working day after disclosure, when urging buyers to quit applying the susceptible edition. The latest variation can be downloaded below.

The Libgcrypt library is an open-supply cryptographic toolkit presented as section of GnuPG application suite to encrypt and indication information and communications. An implementation of OpenPGP, it really is used for digital security in several Linux distributions these kinds of as Fedora and Gentoo, while it isn’t really as widely utilized as OpenSSL or LibreSSL.

According to GnuPG, the bug seems to have been introduced in 1.9. through its enhancement period two several years ago as section of a alter to “lower overhead on generic hash publish operate,” but it was only spotted very last 7 days by Google Challenge Zero.

Hence all an attacker wants to do to set off this critical flaw is to send out the library a block of specifically-crafted info to decrypt, thus tricking the software into jogging an arbitrary fragment of destructive code embedded in it (aka shellcode) or crash a application (in this case, gpg) that relies on the libgcrypt library.

“Exploiting this bug is uncomplicated and therefore fast action for 1.9. buyers is expected,” Libgcrypt author Werner Koch famous. “The 1.9. tarballs on our FTP server have been renamed so that scripts will not be equipped to get this version any more.”

Found this write-up fascinating? Follow THN on Facebook, Twitter  and LinkedIn to study a lot more distinctive content we post.


Some areas of this write-up are sourced from:
thehackernews.com

Previous Post: «Lebanese Apt Group With Suspected Links To Hezbollah Breached 250 Lebanese APT group with suspected links to Hezbollah breached 250 servers worldwide

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • Google Discloses Severe Bug in Libgcrypt Encryption Library—Impacting Many Projects
  • Lebanese APT group with suspected links to Hezbollah breached 250 servers worldwide
  • Firms with exposed IoT have a higher concentration of other security problems
  • As SolarWinds spooks tech firms into rechecking code, some won’t like what they find
  • Microsoft 365 Becomes Haven for BEC Innovation
  • WordPress Pop-Up Builder Plugin Flaw Plagues 200K Sites
  • Cyber-Cop Charged with Forgery and Bigamy
  • Miss England Held to Ransom by Cyber-attackers
  • Flaws in open source library used by DoD, IC for satellite imagery could lead to system takeovers
  • Texas Tech Company Scoops Fourth Equality Title

Copyright © TheCyberSecurity.News, All Rights Reserved.