Bug#822826: gpg: Insecure default cipher for --symmetric

2016-04-28 Thread Piotr Chmielnicki
control: reassign -1 gnupg 1.4.18-7+deb8u1 On 04/28/2016 08:47 AM, Mattia Rizzolo wrote: > control: reassign -1 gnupg > > On Wed, Apr 27, 2016 at 10:26:34PM +0200, Piotr Chmielnicki wrote: >> Package: gpg > the package name is 'gnupg', not 'gpg'. Sorry. >> Version: gnupg > and what kind of version

Bug#822826: gpg: Insecure default cipher for --symmetric

2016-04-27 Thread Mattia Rizzolo
control: reassign -1 gnupg On Wed, Apr 27, 2016 at 10:26:34PM +0200, Piotr Chmielnicki wrote: > Package: gpg the package name is 'gnupg', not 'gpg'. > Version: gnupg and what kind of version is this, anyway? I'm reassigning to the right package, without any version, since you coulnd't provide

Bug#822826: gpg: Insecure default cipher for --symmetric

2016-04-27 Thread Piotr Chmielnicki
Package: gpg Version: gnupg Severity: normal Tags: security Hello, The default cipher in gpg and gpg2 for symmetric encryption is CAST-5. CAST-5 block size is 64 bits and the cipher is used in CFB mode. CFB mode in vulnerable to a practical attack when the size of the ciphertext is close to sqrt(