[Debian-med-packaging] Bug#836553: poretools: short gpg key used in script

D Haley mycae at gmx.com
Sat Sep 3 22:34:33 UTC 2016


Package: poretools
Version: 0.5.1-1
Severity: important

Dear Maintainer,

Your package appears to contain commands which use a short gpg-key
ID. These have recently been identified as potential security concerns,
due to a chance that the wrong key can be imported in the case of a
forced key-ID collision [1].

The affected file is:
 Dockerfile [2]

Its not clear to me that the affected file is actually used in the build
script, but it may be referenced somewhere in the package

Please consider upgrading to a full key ID, for example, replace the command:

 gpg --keyserver <keyserver> --recv-keys <key_short_fingerprint> 

with

 gpg --keyserver  <keyserver> --recv-keys <key_full_id>

eg (not specific to your package):

 gpg --keyserver keyring.debian.org --recv-keys 05C3E651

becomes:

 gpg --keyserver keyring.debian.org --recv-keys 0x0D59D2B15144766A14D241C66BAF400B05C3E651


(Note the tail bytes are the same)

This has previously been forwarded to the security team, who advised to
report individual public bugs against each package - hence this bug.

[1] http://lwn.net/Articles/697417
[2] http://http.debian.net/debian/pool/main/p/poretools/poretools_0.5.1.orig.tar.gz 



More information about the Debian-med-packaging mailing list