#endtoendcrypto — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #endtoendcrypto, aggregated by home.social.
-
When looking at the changes towards the new 2.5.19 version of #GnuPG, there are many small things; like a way to use OCB for symmetric-only encryption, a few defect fixes and improvements.
Not that exciting, but maintenance of the well known #LibrePGP, OpenPGPv4 and CMS capable crypto engine.... you may want to know anyhow. ;)
https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html
https://dev.gnupg.org/T7998 -
Dear GnuPG packagers and builders, please upgrade libgcrypt to v1.12.2 to remove a denial of service vulnerability (estimated CVSS 3.1: AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H -- 7.5 (HIGH)) Releases of other stable versions of libgcrypt are available as well.
(GnuPG versions >= 2.5.7 are not affected due to the use of a different encryption API.)
See https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000503.html for details.
-
Details about the (ongoing) response to https://gpg.fail/ from GnuPG's side:
* https://www.gnupg.org/blog/20251226-cleartext-signatures.html
* https://dev.gnupg.org/T7906 Memory Corruption in ASCII-Armor Parsing
* https://dev.gnupg.org/T7900 (overview)
Please upgrade to GnuPG 2.5.16, 2.4.9 or #Gpg4win 5.0.0-beta479 which already have the fix for what (currently) is seen to be the only major defect: T7906.(Researchers - Thanks! - found defects in GnuPG, Sequoia-PG, Minisign and age.)
-
If you are using the PDF viewer #Okular_from #Gpg4win, please upgrade to version 4.4.1 as this version fixes a severe vulnerability in the freetype library.
:download: https://www.gpg4win.org/download.html
Vulnerability details:
https://euvd.enisa.europa.eu/enisa/EUVD-2025-6367 🛡️There are other good things in Gpg4win 4.4.1, for example
* improvements in the Outlook Add-in (GpgOL)
* a better Kleopatra
* GnuPG upgraded to v2.4.8 -
Better handling of certificates and public keys
with #Gpg4win v4.4.0's improved crypto manager _Kleopatra_.It also comes with #GnuPG v2.4.7 for Windows. Workflows that profit from several signatures on a file
profit as well.https://gpg4win.org/version4.4.html <-- see what else is new.
-
#Gpg4win v4.3.0 <- freshly announced.
New is that encrypted files with email structure from disk can be shown.
Kleopatra and the Outlook Add-in gain features and resilience for less common situations (like Apple mail attachments or unreliable S/MIME CRLs).
Includes #GnuPG v2.4.4 and its many improvements.
https://lists.wald.intevation.org/pipermail/gpg4win-announce/2024/000104.html