security patches

Johan Wevers johanw@vulcan.xs4all.nl
Tue Sep 25 23:18:02 2001


Kai Raven wrote:


> can somebody give me a short summary for which vulnerabilities GnuPG
> 1.0.6 is patched/fixed or not affected?
> -ADK
GPG does not support ADK's at all and hopefully never will so it is not vulnerable to bugs in the ADK implementation.
> -Klima-Rosa
Solved.
> -ASCII Armor Parser
This has to do with windows programs saving encrypted DLL's automagically in a system directory and then overwriting system DLL's. GnuPG for win32 does not do this, and on Unix this is no issue at all.
> -Key Validity
Solved.
> (that's all?)
AFAIK, until now, yes. -- ir. J.C.A. Wevers // Physics and science fiction site: johanw@vulcan.xs4all.nl // http://www.xs4all.nl/~johanw/index.html PGP/GPG public keys at http://www.xs4all.nl/~johanw/pgpkeys.html