posted by Jorge in open source // 1035 days 2 hours 31 minutes ago
A pair of security bugs in cryptography software could allow an attacker to insert content into a digitally signed message or forge signatures on files.
The flaws lie in the open-source GNU Privacy Guard software, also known as GnuPG and GPG, the GnuPG group said in two alerts. The software, a free replacement for the Pretty Good Privacy cryptographic technology, ships with many open-source operating systems such as FreeBSD, OpenBSD and many Linux distributions.