Publishing details

Changelog

gnupg2 (2.0.26-6ubuntu1) vivid; urgency=medium

  * Merge from Debian, remaining changes:
    - Drop sh prefix from openpgp test environment as it leads to exec
      invocations of sh /bin/bash leading to syntax errors from sh.  Fixes
      FTBFS detected in Ubuntu saucy archive rebuild.
    - Add udev rules to give gpg access to some smartcard readers;
      Debian #543217.
    - debian/gnupg2.udev: udev rules to set ACLs on SCM smartcard readers.
    - Add upstart user job for gpg-agent.
    - debian/control: drop dirmngr to Suggests as it is in universe.

gnupg2 (2.0.26-6) unstable; urgency=medium

  * Avoid NULL dereference with opaque MPI.

gnupg2 (2.0.26-5) unstable; urgency=medium

  * import bug-fixes from upstream
    (Closes: #773415, #773469, #773471, #773472, #773423)
  * Fixes CVE-2015-1606 "Use after free, resulting from failure to skip
    invalid packets", CVE-2015-1607 "memcpy with overlapping ranges,
    resulting from incorrect bitwise left shifts" (Closes: #778577)

gnupg2 (2.0.26-4) unstable; urgency=medium

  [ David Prévot ]
  * Update POT and PO files, and ensure the translations get rebuild
  * Update French translation (Closes: #769574)
  * Update Ukrainian translation, thanks to Yuri Chornoivan
  * Update German translation, thanks to Werner Koch
  * Update Danish translation, thanks to Joe Hansen
  * Update Japanese translation, thanks to NIIBE Yutaka
  * Update Chinese (traditional) translation, thanks to Jedi Lin
  * Update Russian translation, thanks to Ineiev
  * Update Polish translation, thanks to Jakub Bogusz
  * Update Spanish translation, thanks to Manuel "Venturi" Porras Peralta
    (Closes: #770727)
  * New Dutch translation, thanks to Frans Spiesschaert (Closes: #770981)

  [ Daniel Kahn Gillmor ]
  * bugfix and cryptographic safety changes imported from upstream:
   - Avoid regression when adding subkeys with strong s2k algorithms
     (Closes: #772780) Thanks, NIIBE Yutaka
   - Allow french translation to work when prompting for passphrase.
   - add build and runtime support for larger RSA keys (Closes: #739424)
   - fix runtime errors on bad input (Closes: #771987)
   - deprecate insecure one-argument variant for gpg --verify of detached
     signatures (Closes: #771992)
   - initialize trustdb before trying to clear it (Closes: #735363)
   - default to issuing SHA256 signatures for RSA
   - avoid relying on MD5 signatures
   - show v3 key fingerprints as all zero (OpenPGPv3 is deprecated)
 -- Marc Deslauriers <email address hidden>   Wed, 11 Mar 2015 08:25:01 -0400

Available diffs

Builds

Package files