logo       

bug#380: marked as done (gnupg version has security hole; easy to upgrade): msg#00110

linux.bbc.bugs

Subject: bug#380: marked as done (gnupg version has security hole; easy to upgrade)

Your message dated Wed, 21 May 2003 07:53:37 -0700
with message-id <E19IUyH-0000T1-00@xxxxxxxxxxxxxxxxxxxx>
and subject line Bug modified from CVS checkin
has caused the attached bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)

Nick Moffitt
(administrator, LNX-BBC bugs database)

--------------------------------------
Received: (at submit) by bugs.lnx-bbc.org; 21 May 2003 04:12:39 +0000
>From me@xxxxxxxxxxx Tue May 20 21:12:39 2003
Received: from [63.149.73.20] (helo=vorpal.notabug.com ident=qmailr)
by gargoyle.lnx-bbc.org with smtp (Exim 3.35 #1 (Debian))
id 19IKxy-000243-00
for <submit@xxxxxxxxxxxxxxxx>; Tue, 20 May 2003 21:12:39 -0700
Received: (qmail 18703 invoked from network); 21 May 2003 04:15:44 -0000
Received: from 12-207-74-63.client.attbi.com (HELO aaronsw.com) (12.207.74.63)
by 0 with SMTP; 21 May 2003 04:15:44 -0000
Date: Tue, 20 May 2003 23:15:44 -0500
Mime-Version: 1.0 (Apple Message framework v552)
Content-Type: text/plain; charset=US-ASCII; format=flowed
Subject: gnupg version has security hole; easy to upgrade
From: Aaron Swartz <me@xxxxxxxxxxx>
To: submit@xxxxxxxxxxxxxxxx
Content-Transfer-Encoding: 7bit
Message-Id: <E44644B8-8B42-11D7-B62A-0003936780B2@xxxxxxxxxxx>
X-Mailer: Apple Mail (2.552)

Package: gnupg

The version of gnupg listed in CVS has a recently-discovered security
hole. Upgrading it to the latest version (which doesn't have the
security hole) is easy:

In Makefile let:
GARVERSION = 1.2.2

and in checksums:
01cf9c6b949603d0511f6fc07bc758d2 download/gnupg-1.2.2.tar.gz

When I tested these modifications on my machine, things built and
tested fine.

- Aaron Swartz <http://www.aaronsw.com/>


---------------------------------------
Received: (at 380-done) by bugs.lnx-bbc.org; 21 May 2003 14:53:37 +0000
>From dave@xxxxxxxxxxxxxxxxxxxx Wed May 21 07:53:37 2003
Received: from dave by gargoyle.lnx-bbc.org with local (Exim 3.35 #1 (Debian))
id 19IUyH-0000T1-00
for <380-done@xxxxxxxxxxxxxxxx>; Wed, 21 May 2003 07:53:37 -0700
To: 380-done@xxxxxxxxxxxxxxxx
Subject: Bug modified from CVS checkin
Message-Id: <E19IUyH-0000T1-00@xxxxxxxxxxxxxxxxxxxx>
From: Dave Barry <dave@xxxxxxxxxxxxxxxxxxxx>
Date: Wed, 21 May 2003 07:53:37 -0700

Closes: 380
NUV from Aaron Swartz


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise