gnupg 1.2.4-4ubuntu2.2 source package in Ubuntu

Changelog

gnupg (1.2.4-4ubuntu2.2) warty-security; urgency=low

  * SECURITY UPDATE: Fix potential signature verification bypass.
  * Add debian/patches/23_verify_exit_code.dpatch:
    - Security fix for a verification weakness in gpgv.  Some input
      could lead to gpgv exiting with 0 even if the detached signature
      file did not carry any signature.  This is not as fatal as it
      might seem because the suggestion as always been not to rely on
      th exit code but to parse the --status-fd messages.  However it
      is likely that gpgv is used in that simplified way and thus we
      do this release.  Same problem with "gpg --verify" but nobody
      should have used this for signature verification without
      checking the status codes anyway.
    - Upstream patch from 1.4.2.1.
    - CVE-2006-0455

 -- Martin Pitt <email address hidden>   Fri, 17 Feb 2006 11:11:51 +0000

Upload details

Uploaded by:
Martin Pitt
Uploaded to:
Warty
Original maintainer:
James Troup
Architectures:
any
Section:
utils
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
gnupg_1.2.4.orig.tar.gz 3.3 MiB 09c78891a6ef6b40b698ddd2cc9d2ad23e5eed14e30849d9d1f75d2ebe1ef199
gnupg_1.2.4-4ubuntu2.2.diff.gz 56.3 KiB 96052dda9b1473154fc8141f1ce379054eecfb3fe4a438bfdf7accee5f32e747
gnupg_1.2.4-4ubuntu2.2.dsc 621 bytes 039b638f53328ed737fcabb8bb9f561b43de03c4aec8415f8ee83316388f0323

View changes file

Binary packages built by this source

gnupg: No summary available for gnupg in ubuntu warty.

No description available for gnupg in ubuntu warty.