CAN-2005-2096 - zlib issue

David Shaw dshaw at jabberwocky.com
Fri Jul 15 15:43:46 CEST 2005


On Sun, Jul 10, 2005 at 11:54:54PM +0200, Florian Weimer wrote:
> * David Shaw:
> 
> > The bundled zlib is GnuPG is 1.1.4.  To my understanding, it is not
> > vulnerable.  The problem is only on zlib 1.2 and later.
> 
> Thanks for looking into this.  I should have checked the version of
> the included copy; sorry for the noise.

I'm glad you posted.  I had checked zlib, but a second look to double
check (particularly on a security problem) is always good.  Plus, it
got the information to the mailing list, which I had neglected to do
:)

David



More information about the Gnupg-devel mailing list