You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PGPy 0.6.0 decrypts SED packets (typ 9). This is problematic,
because it allows attackers to downgrade SEIPDv1 (typ 18) packets
to SED packets, effectively stripping the authentication that
SEIPDv1 provides, making the ciphertext malleable, and allowing
EFAIL-style exfiltration attacks.
PGPy 0.6.0 decrypts SED packets (typ 9). This is problematic,
because it allows attackers to downgrade SEIPDv1 (typ 18) packets
to SED packets, effectively stripping the authentication that
SEIPDv1 provides, making the ciphertext malleable, and allowing
EFAIL-style exfiltration attacks.
https://www.metzdowd.com/pipermail/cryptography/2015-October/026685.html
To protect all SEIPDv1-encrypted messages, SED packets must not
be decrypted.
The text was updated successfully, but these errors were encountered: