Slackware-10.2 ChangeLog (2006-03-14)

Mon Mar 13 20:42:48 CST 2006

  • patches/packages/gnupg-1.4.2.2-i486-1.tgz
    There have been two security related issues reported recently with GnuPG.
    From the GnuPG 1.4.2.1 and 1.4.2.2 NEWS files:
    Noteworthy changes in version 1.4.2.2 (2006-03-08)
    * Files containing several signed messages are not allowed any
    longer as there is no clean way to report the status of such
    files back to the caller. To partly revert to the old behaviour
    the new option –allow-multisig-verification may be used.
    Noteworthy changes in version 1.4.2.1 (2006-02-14)
    * Security fix for a verification weakness in gpgv. Some input
    could lead to gpgv exiting with 0 even if the detached signature
    file did not carry any signature. This is not as fatal as it
    might seem because the suggestion as always been not to rely on
    th exit code but to parse the –status-fd messages. However it
    is likely that gpgv is used in that simplified way and thus we
    do this release. Same problem with “gpg –verify” but nobody
    should have used this for signature verification without
    checking the status codes anyway. Thanks to the taviso from
    Gentoo for reporting this problem.
    (* Security fix *)
  • news/2006/03/14/slackware-10.2-changelog.txt
  • Last modified: 12 months ago
  • by Giuseppe Di Terlizzi