Format: 1.8 Date: Thu, 26 May 2022 12:24:46 +0200 Source: gnupg2 Binary: gpgconf gnupg-agent gpg-agent gpg-wks-server gpg-wks-client scdaemon gpgsm gpg gnupg gnupg2 gpgv gpgv2 dirmngr gpgv-udeb gpgv-static gpgv-win32 gnupg-l10n gnupg-utils Architecture: armhf armhf_translations Version: 2.2.4-1ubuntu1.5 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: David Fernandez Gonzalez Description: dirmngr - GNU privacy guard - network certificate management service gnupg - GNU privacy guard - a free PGP replacement gnupg-agent - GNU privacy guard - cryptographic agent (dummy transitional packa gnupg-l10n - GNU privacy guard - localization files gnupg-utils - GNU privacy guard - utility programs gnupg2 - GNU privacy guard - a free PGP replacement (dummy transitional pa gpg - GNU Privacy Guard -- minimalist public key operations gpg-agent - GNU privacy guard - cryptographic agent gpg-wks-client - GNU privacy guard - Web Key Service client gpg-wks-server - GNU privacy guard - Web Key Service server gpgconf - GNU privacy guard - core configuration utilities gpgsm - GNU privacy guard - S/MIME version gpgv - GNU privacy guard - signature verification tool gpgv-static - minimal signature verification tool (static build) gpgv-udeb - minimal signature verification tool (udeb) gpgv-win32 - GNU privacy guard - signature verification tool (win32 build) gpgv2 - GNU privacy guard - signature verification tool (dummy transition scdaemon - GNU privacy guard - smart card support Launchpad-Bugs-Fixed: 1844059 Changes: gnupg2 (2.2.4-1ubuntu1.5) bionic-security; urgency=medium . * SECURITY UPDATE: Certificate Spamming Attack through SKS (LP: #1844059) - debian/patches/CVE-2019-13050-1.patch: add option to only accept self-signatures when importing a key in g10/import.c, g10/options.h and doc/gpg.texi. - debian/patches/CVE-2019-13050-2.patch: add fallback when importing self-signatures only in g10/import.c. - debian/patches/CVE-2019-13050-3.patch: add "self-sigs-only" and "import-clean" to the keyserver options in g10/gpg.c and doc/gpg.texi. - debian/patches/CVE-2019-13050-4.patch: fix regression by ensuring KEYID is available on a pending package in g10/import.c. - debian/patches/CVE-2019-13050-5.patch: prevent fallback from being used if the options are already used in g10/import.c. - CVE-2019-13050 Checksums-Sha1: 3ccf2b1b38db352ce76aaefa52b1109200a4f6bc 879416 dirmngr-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 3a9ebe0195f3ab845ce1ae55f79c9d2f456d9093 274508 dirmngr_2.2.4-1ubuntu1.5_armhf.deb 9d5944b9ea2b4eb9494b084e8af3b355417c1727 456644 gnupg-utils-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 480bb77a2fab92418234b2611258fe065b072b52 107080 gnupg-utils_2.2.4-1ubuntu1.5_armhf.deb d06705469d6b54057e7604182f1bc318e097369c 19094 gnupg2_2.2.4-1ubuntu1.5_armhf.buildinfo 836ec15d23c1a1027e692d188bec5fe451ee5584 2307527 gnupg2_2.2.4-1ubuntu1.5_armhf_translations.tar.gz 70e40a1d467d1bafcb77f8beb0102dffda209d87 249320 gnupg_2.2.4-1ubuntu1.5_armhf.deb 9b2b594b0222b2bda55f4b27e7347ff46ad0b556 914812 gpg-agent-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb c7d3a479d10fc830a780b41e51b0dad53a127585 188528 gpg-agent_2.2.4-1ubuntu1.5_armhf.deb 442c0ff020cd621a8e814d39c1b13945d70e1231 1241624 gpg-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb d48d41a53fb3e5c5d40dd76afad29a4921ba0698 259508 gpg-wks-client-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 57886b391510bca266671d542652a297f5495725 76492 gpg-wks-client_2.2.4-1ubuntu1.5_armhf.deb 7051c0f92f681fd79352d0b80711f1c2ef0ba871 232980 gpg-wks-server-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 85541d2384409c4ba90f5f09bb80f36db068c2a7 71756 gpg-wks-server_2.2.4-1ubuntu1.5_armhf.deb 6a8c0b408e97b102db8b98d3584cd0cc5ff4ef6b 408632 gpg_2.2.4-1ubuntu1.5_armhf.deb 982022bd5f75319001f84ef220b29d009b1d1ad8 339608 gpgconf-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 93e9ca4750a7317a1454e0760849492c29a5199a 105952 gpgconf_2.2.4-1ubuntu1.5_armhf.deb 49ff5869ea989ebc681fcc4b78a99cfbb1a040a2 560100 gpgsm-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb d52c4e428884304f4bd77604aa88849a54650756 183368 gpgsm_2.2.4-1ubuntu1.5_armhf.deb 27915e7965d0ae8c9e8d8be528e2f5e623909770 578224 gpgv-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb f688c934f469a428ee99ee1a413631c0d762d84a 623248 gpgv-static-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb a738755af8271c93b0425b7c240bf739b8bfef42 727324 gpgv-static_2.2.4-1ubuntu1.5_armhf.deb 3c3254b8e60b63b008c53dc21e60840f35ed0af9 158264 gpgv-udeb_2.2.4-1ubuntu1.5_armhf.udeb b6fa35eb57014ff2cae7d27722fbded60f654631 168128 gpgv_2.2.4-1ubuntu1.5_armhf.deb 01c676900d3dc798059d3d2db72863faa6bfa3ac 441752 scdaemon-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 180d6a6c3e8cef2d18d4a9041bfc7627ff6afbe5 157092 scdaemon_2.2.4-1ubuntu1.5_armhf.deb Checksums-Sha256: 3550891d982b2f916900c6704451bc4c43ab61aaad5541bb5eb8456893716001 879416 dirmngr-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 5b2eb0dd64fdd932a38b86ab55f0f8f3247b794d7b145aa74e856169136f0660 274508 dirmngr_2.2.4-1ubuntu1.5_armhf.deb cf5e9281427c02d5736076ec3cd39251b0c853687b28f45620234280820ff529 456644 gnupg-utils-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb ef44190f3bbf314487416b0bb0efd49a4015b9a783ad32f67ea4625311243fd2 107080 gnupg-utils_2.2.4-1ubuntu1.5_armhf.deb 860bbc3f5702c7cbfc48557752a0cfe1b7e844ea02fc6fd1c393be1e67be0003 19094 gnupg2_2.2.4-1ubuntu1.5_armhf.buildinfo c7d8fd1b80f8fec2347f5d4d9a13cba3526663f0d3c0a8ed78d510e8aa49dc2b 2307527 gnupg2_2.2.4-1ubuntu1.5_armhf_translations.tar.gz 1f1c43de7b56afcdf0c3a417e6ae2de44ed6f7bcf1816f60bf8c93ddfd39881c 249320 gnupg_2.2.4-1ubuntu1.5_armhf.deb be9c47254496b3941157eb7f1f62f2647b6070708cf9973c65ec6450fd6507b0 914812 gpg-agent-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb eb9f8a0688704829b60c6d9b20ecbf078d17e90fdc2863312a83172fd5fd799e 188528 gpg-agent_2.2.4-1ubuntu1.5_armhf.deb 999930bb1bda206b8456b7e364f07a90d4513a7e029ef3bdc90361e22fb59bda 1241624 gpg-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 893cffc71e31ad354383810a133a0e3a3730179b8c6c92b320edce411fe1e49e 259508 gpg-wks-client-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 4a094ef8191493b0e6dbb4df3976a7a2680f4d2a2c3edf1b0260a88729c59935 76492 gpg-wks-client_2.2.4-1ubuntu1.5_armhf.deb c10fb3bad270b9b7264fb4681513d3fe9d35340997d84b20984b1cbdfbfe9705 232980 gpg-wks-server-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb fa212552d7891e617840365c0a143b6c07a10980fdabdd94a485b0904e27dfa1 71756 gpg-wks-server_2.2.4-1ubuntu1.5_armhf.deb d1120ae78906cbb706243666f655396b8280e771f1b57fb78ffc7fd25cf9e88a 408632 gpg_2.2.4-1ubuntu1.5_armhf.deb 7a4a188ade6f9c42d23ede457759f9f242e3471dbca7d669e93c275ed54fb0c6 339608 gpgconf-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 9b3cdccdb78b8f7277c9fad36e62aeb0e5991bbeecb4ba6350918aeb8865660b 105952 gpgconf_2.2.4-1ubuntu1.5_armhf.deb ea40b1751999f032404a8d9efc9cab21cbf6e69e389594e09d531cf552e0a408 560100 gpgsm-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 8c2fd48d2d19001b55aa53a8cf9532d8b7a4f033b042311e4a8c92724e3a829b 183368 gpgsm_2.2.4-1ubuntu1.5_armhf.deb 48993f0d39db2b0cdcaf7098b1effd2c110557ecfea80fd3b2fd7a82f0090fe6 578224 gpgv-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 0e51cb87bd4716f0af1586bb59f747d263bd641e26a96453330f2b774552dc6d 623248 gpgv-static-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 6dbe8457c2fcf9d750ed4ac38154031dbdaedf4a2b061c65c81dc39de13fbb2e 727324 gpgv-static_2.2.4-1ubuntu1.5_armhf.deb 93cbd2a301093a12f2a7755b854ec1a9e7d0b0a2f49274ef8e99344ed14ffc1b 158264 gpgv-udeb_2.2.4-1ubuntu1.5_armhf.udeb db077550ea2e2f37b89ecc6417661f6b7fa6873889dfdb885e9e4c8efa8807aa 168128 gpgv_2.2.4-1ubuntu1.5_armhf.deb e231acf68ee3cc195933357fe828538b5573c3b8472416e02df67e7a28708723 441752 scdaemon-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb ff606eaebb44b2df52fd6042e02c5b21188ea759681d7506f10b1958efff8a08 157092 scdaemon_2.2.4-1ubuntu1.5_armhf.deb Files: 6483577a0be5be2642e8ba22143664da 879416 debug optional dirmngr-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 386366fdbff9a79f07358efa75d8ce73 274508 utils optional dirmngr_2.2.4-1ubuntu1.5_armhf.deb bb1d47da2520cd6325e213c2eecb366e 456644 debug optional gnupg-utils-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 07b1d9df441e055d242b6ee3685140e2 107080 utils optional gnupg-utils_2.2.4-1ubuntu1.5_armhf.deb ce0f2ae4ff747ef3ccdb088c9e908f1c 19094 utils optional gnupg2_2.2.4-1ubuntu1.5_armhf.buildinfo f3f2fad1765d7f3b5b72cb329f27f497 2307527 raw-translations - gnupg2_2.2.4-1ubuntu1.5_armhf_translations.tar.gz d55b4d054cf2d043bcee504e3d68649c 249320 utils optional gnupg_2.2.4-1ubuntu1.5_armhf.deb 0e8958dea2d97a1691996873c4f99cd9 914812 debug optional gpg-agent-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb a5576cd353cb3b47d30e674cef5cf1e2 188528 utils optional gpg-agent_2.2.4-1ubuntu1.5_armhf.deb 6e563acd62aea296ee79062a1b932906 1241624 debug optional gpg-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 0f49c14d2e1926a14565669129d56d6b 259508 debug optional gpg-wks-client-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb d56cfb8955e672836228aef2797fef72 76492 utils optional gpg-wks-client_2.2.4-1ubuntu1.5_armhf.deb 03754018d9301de91996905ce376b9d7 232980 debug optional gpg-wks-server-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb b156fc7a701f1f0fcf171a702460312b 71756 utils optional gpg-wks-server_2.2.4-1ubuntu1.5_armhf.deb e6e198a9793d0424aa8d27abc0498066 408632 utils optional gpg_2.2.4-1ubuntu1.5_armhf.deb a2213eb17bbeab57b86c8ca3b6025a03 339608 debug optional gpgconf-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 671ef2eef37276333aaf3b5b6d7e50f3 105952 utils optional gpgconf_2.2.4-1ubuntu1.5_armhf.deb d30e2f4846409885a85b3eae827bf620 560100 debug optional gpgsm-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 3bda5e3a80bf85aed445bbcaa3673612 183368 utils optional gpgsm_2.2.4-1ubuntu1.5_armhf.deb 406a5f3dfc327e1e45b6732889136585 578224 debug optional gpgv-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 56613bd15e51c3cfce4bcd5673fb551d 623248 debug optional gpgv-static-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb 74f8c200ac9dc26e80ee58cd03d2e8cc 727324 utils optional gpgv-static_2.2.4-1ubuntu1.5_armhf.deb 1cf9029211f2a598b68892175b95e1c3 158264 debian-installer optional gpgv-udeb_2.2.4-1ubuntu1.5_armhf.udeb a02761e49197017d4989577368d2dbd7 168128 utils important gpgv_2.2.4-1ubuntu1.5_armhf.deb d8fa0d49ba009eda5f2dceeab315f54a 441752 debug optional scdaemon-dbgsym_2.2.4-1ubuntu1.5_armhf.ddeb d09e16de71478c75e3720e8045bbe17e 157092 utils optional scdaemon_2.2.4-1ubuntu1.5_armhf.deb Original-Maintainer: Debian GnuPG Maintainers