Author Topic: Version Update Request  (Read 1638 times)

Storm

  • Full Member
  • ***
  • Posts: 156
    • View Profile
    • http://
Version Update Request
« on: March 10, 2006, 12:21:30 am »
Hi all,

For the developers, when time permits, I would like to request the upgrade of gnupg to 1.4.2.2, due to a recently announced vulnerability in versions of gpg older than this.

In a nutshell, an attacker could insert arbitrary data into a non-detached signature, which gnupg would then report as a good sig.

I need to find a place where I can install a build environment, else I would have a go at compiling it. If time permits, I will try to find place to set this up...

--Storm
Zaurus SL-5500/Hentges OZ 3.5.4.1
Ambicom WL1100-CF wireless card
Desktop: Debian/GNU Linux (unstable)