[Announce] Gpg4win 1.0.3 released (security fix)

Werner Koch wk at gnupg.org
Mon Jun 26 16:00:09 CEST 2006


Hi!

We are pleased to announce the availibility of Gpg4win, version 1.0.3.

* This version contains security fixes for the GnuPG and Sylpheed-Claws
  components.  *Updating to this version is strongly recommended*.

* Please also make sure to subscribe to the new gpg4win announcement
  mailing list.  We might stop in the future to cross post
  announcements to the general GnuPG annoucement list.  See:
    http://lists.wald.intevation.org/mailman/listinfo/gpg4win-announce


About Gpg4win
-------------

The Gpg4win project aims at updating the Gpg4win Windows installation
package with GnuPG encryption tool, associated applications and
documentation on a regular basis.  Especially the documentation
(handbooks "Einsteiger" and "Durchblicker") are directly maintained as
part of the gpg4win project.

It is an international project. Due to the origin of the project the
German language is fully supported.  As of now the the handbooks are
only available in German.  People helping with translations are very
welcome!

The main difference compared to all other similar approaches (mainly
GnuPP, GnuPT, Windows Privacy Tools and GnuPG-Basics) is that the
first thing developed was the *gpg4win-Builder*. This builder allows
to easily create new gpg4win.exe installers with updated components.

The builder runs on any decent Unix system, preferable Debian
GNU/Linux.  Almost all products are automatically cross-compiled for
integration into the installer.

With this concept it is hoped to *prevent quick aging of the*
*installer package*. This is due to easier updating and less
dependancy on single developers.


Noteworthy changes in version 1.0.3 (2006-06-26)
------------------------------------------------

 * Fixed a security related bug in GnuPG (CVE-2006-3082).

 * Updated Sylpheed-Claws due to security problems.

 * Included components are:
	GnuPG: 1.4.4  [*]
	WinPT: 0.12.3  [*]
	GPA:   0.7.3
	GPGol: 0.9.10
	GPGee: 1.3.1
	Sylpheed-Claws: 2.3.1  [*]
	Einsteiger:     2.0.2 
	Durchblicker:   2.0.2 
   (Marked packages are updated since the last release) 


Installation
------------

For installation instructions, please visit http://www.gpg4win.org or
read on.

Developers who want to *build an installer* need to get the following
files from http://wald.intevation.org/projects/gpg4win/ :

  gpg4win-1.0.3.tar.bz2 (3.9M)
  gpg4win-1.0.3.tar.bz2.sig

The second file is a digital signature of the the first file.  Either
check that this signature is fine or compare with the checksums given
below.  (see also http://www.gnupg.org/download/integrity_check.html)

The *ready to use installer* is available at:

  http://ftp.gpg4win.org/gpg4win-1.0.3.exe  (6.2M)
  http://ftp.gpg4win.org/gpg4win-1.0.3.exe.sig

Or using the ftp protocol at:

  ftp://ftp.gpg4win.org/gpg4win/gpg4win-1.0.3.exe  (6.2M)
  ftp://ftp.gpg4win.org/gpg4win/gpg4win-1.0.3.exe.sig

SHA1 and MD5 checksums for these files are given below.

If you don't need the German PDF manuals, you might alternatively
download the "light" version of the installer:

  http://ftp.gpg4win.org/gpg4win-light-1.0.3.exe  (4.6M)
  http://ftp.gpg4win.org/gpg4win-light-1.0.3.exe.sig

or using the ftp protocol at:

  ftp://ftp.gpg4win.org/gpg4win/gpg4win-1.0.3.exe  (4.6M)
  ftp://ftp.gpg4win.org/gpg4win/gpg4win-1.0.3.exe.sig


A separate installer with the the sources used to build the above
installer is available at:

  ftp://ftp.gpg4win.org/gpg4win/gpg4win-src-1.0.3.exe  (41M)
  ftp://ftp.gpg4win.org/gpg4win/gpg4win-src-1.0.3.exe.sig

Most people don't need this source installer; it is merely stored on
that server to satisfy the conditions of the GPL.  In general it is
better to get the gpg4win builder tarball (see above) and follow the
instructions in the README to build new installers; building the
installer is not possible on Windows machines and works best on
current Debian GNU/Linux systems (we use the mingw32 package from
Sid).

SHA1 checksums are:

fb010c9d4ee9e4d51b2b43034562f39eb6b88cbf  gpg4win-1.0.3.exe
bdb1065aaa8f72fcd13158712f2b479586d3d677  gpg4win-light-1.0.3.exe
fa5e30e95227edda40f53dfc424239de06f0980a  gpg4win-src-1.0.3.exe
7f0877dbde8e20e0b50288fefe4f77f1574bc50b  gpg4win-1.0.3.tar.bz2

MD5 checksums are:

543343e59df88354627e018e0d3052ce  gpg4win-1.0.3.exe
c5ea9009beb27e16f955cc83ca5573ef  gpg4win-light-1.0.3.exe
0d247c343c5623cb459b5debdadd30f7  gpg4win-src-1.0.3.exe
6ed1496b1edacfc7d7416e4155e3fe9e  gpg4win-1.0.3.tar.bz2


We like to thank the authors of the included packages, the NSIS
authors, all other contributors and first of all, those folks who
stayed with us and tested the early releases of gpg4win.


Happy hacking,

  Jan, Marcus, Timo and Werner


-- 
Werner Koch                                      <wk at gnupg.org>
The GnuPG Experts                                http://g10code.com
Join the Fellowship and protect your Freedom!    http://www.fsfe.org



_______________________________________________
Gnupg-announce mailing list
Gnupg-announce at gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-announce




More information about the Gnupg-devel mailing list