Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upcode audit vs SigSpoof: Spoofing signatures in GnuPG - CVE-2018-12020 #4070
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment
Hide comment
marmarek
Jul 12, 2018
Member
I've just checked again and it looks to be fine - in no place we mix --verbose output with --status-fd output. Places I've checked:
- verify-git-tag script in qubes-builder - uses
git verify-tag, --verbose isn't used - command verification in builder-github - uses separate fd for status-fd (not stderr), also no --verbose in use
|
I've just checked again and it looks to be fine - in no place we mix
|
marmarek
closed this
Jul 12, 2018
andrewdavidwong
added
the
notanissue
label
Jul 13, 2018
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
adrelanos commentedJul 12, 2018
https://neopg.io/blog/gpg-signature-spoof
https://blog.patternsinthevoid.net/pretty-bad-protocolpeople.html
Does it look like any code changes are advisable?