Executive brief
OpenPGP.js is a JavaScript library used to encrypt and sign messages with PGP encryption. Versions prior to 4.2.0 fail to properly verify whether signature subpackets are cryptographically protected, allowing an attacker to modify certification or revocation signatures. This could trick users into using obsolete or compromised keys for encryption, potentially exposing sensitive communications.
Technical details
The vulnerability stems from improper handling of OpenPGP signature subpackets. The OpenPGP standard distinguishes between hashed (cryptographically protected) and unhashed subpackets; the library failed to validate this distinction and allowed unhashed subpacket data to overwrite information from hashed subpackets. An attacker with the ability to deliver a manipulated key or key update to a victim can exploit this to alter key certification or revocation signatures (CWE-347: Improper Verification of Cryptographic Signature). The attack requires victim interaction (importing or updating a key) but operates over the network. Remediation is available in version 4.2.0 and later.
Affected products
- OpenPGP.js OpenPGP.js prior to 4.2.0
Timeline
- 2019-08-23: disclosed
- 2018-11-05: patched: Security fixes merged into master branch