BUG: Signing and encrypting a single space in textmode is broken

David Shaw dshaw@jabberwocky.com
Tue Apr 23 04:53:01 2002


On Sat, Apr 20, 2002 at 09:32:27PM +0200, Ingo Kl=F6cker wrote:
> [Please cc me as I'm not subscribed to gnupg-devel.]
>=20
> Hi,
>=20
> a KMail user tried to send himself a signed and encrypted message which=
=20
> only contains a single space. After decrypting the received message it=20
> contained some garbage characters and was not signed.

Very interesting bug.  GnuPG was making a good signature, but the
verification side was not correctly handling the zero-length data for
the signature.  The binary garbage you found in the received message
was actually the signature itself.

This is fixed now.

David

--=20
   David Shaw  |  dshaw@jabberwocky.com  |  WWW http://www.jabberwocky.co=
m/
+------------------------------------------------------------------------=
---+
   "There are two major products that come out of Berkeley: LSD and UNIX.
      We don't believe this to be a coincidence." - Jeremy S. Anderson