[Announce] [security fix] GnuPG 1.4.17 released

Kristian Fiskerstrand kristian.fiskerstrand at sumptuouscapital.com
Mon Jun 23 19:21:56 CEST 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 06/23/2014 07:19 PM, Kristian Fiskerstrand wrote:
> On 06/23/2014 06:21 PM, Werner Koch wrote:
>> Hello!
> 
> 
> Hi
> 
> 
>> * Avoid DoS due to garbled compressed data packets.
> 
> 
> Is this CVE-2013-4402 as fixed in 2.0.22 or a new bug?
> 

Nevermind, I notice the git commit comment. Has a CVE been requested
for this already or should I ask for one?

- -- 
- ----------------------------
Kristian Fiskerstrand
Blog: http://blog.sumptuouscapital.com
Twitter: @krifisk
- ----------------------------
Public PGP key 0xE3EDFAE3 at hkp://pool.sks-keyservers.net
fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3
- ----------------------------
Aut dosce, aut disce, aut discede
Either teach, or study, or leave
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJTqGI0AAoJEPw7F94F4Tagzw4P/0dlzt4V+aPvfjfsVDcPKJbT
yMl/W9oeeVofC1T3FkH+k0aQ0M66w/9PcU+pEYgLN0xXUuyqMVn/lodgEFFkU9dG
xSvAWJeBXu6YU30WsdQJD+KGUT38YrdnKqGm0vYPh0OtteJA0JfUdZxD3VlY1Ah4
l0+vLikjLkbPKV6Lnc9E+5N9iqHhLV4/+XGFqF0DueQiRD3bhZ2p5rOwHe7WQ86m
Y+NMUemDO8qCsEcs3Llpc3bR2sbnovPEE22M7OTGrKMG77/VPAxTfZVyjEZ+SeY+
ff6Vlb80eaMPS8DjJdaSLCSEkiW90cA+uzjCAa1/uMWJ03IX4EWiqqbqHu9fn1rE
MZmRTaqc7hhFbdXhYaLIBWCWACWMV9ysZGW/7geJj6JGCE0O2YY8hZ1kRXL+Hkuw
hM42BauUErBcgmTD3ywhkQYkwXbK+P86golxUXzey5EpM+89Yg8noeQYWp4TwWlO
D14emnaCNJZvmQBXjFnmxEseEQV7K/ib0m9nHkS5y2GxYWmEfg9gilbGd6ZDOEDQ
hxzCYmPQjTxlrZYpEKjG46NeH79I/FAAvuXfijnthlGiwny5brfY1vgOLl9o0hQ/
1FobHe9figvcnd7z1/8WJrv+Zp/9ef6df3TZ55Gcxf0FtITdTzCUANuqksZYIDH0
Xt0Rv62WzTed4ufaQlSG
=9GtQ
-----END PGP SIGNATURE-----



More information about the Gnupg-users mailing list