[OTR-dev] Issues with libgcrypt 1.5

Ian Goldberg ian at cypherpunks.ca
Sun Apr 10 10:58:57 EDT 2011


Werner Koch wrote:
> On Wed, 9 Mar 2011 18:19, arfrever.fta [at] gmail said:
> > I have added Libgcrypt 1.5.0-beta1 to Gentoo's main repository on
> > 2011-02-23.
> > Until now, only problem [1] with libotr [2] has been reported.
> > Could you check if it is a bug in Libgcrypt 1.5.0-beta1 or in libotr?
> 
> Well, I need a bit more of info. Which function returns with "invalid
> length"? I need a small test case (w/o any gentoo or KDE specific
> stuff). 

and Kjell Branded (on the otr-dev list wrote):
> FYI: libgcrypt-1.5.0_beta1 seems to throw GPG_ERR_INV_LENGTH errors when
> encrypting/decrypting messages using AES-CTR when their length is not a
> multiple of the block size (16?). This makes libotr unusable with that
> version.

Werner, would it be possible to revert libgcrypt's behaviour to
internally handle a truncated final block for AES-CTR mode?

Thanks,

   - Ian



More information about the OTR-dev mailing list