Branches for Edgy

Name Status Last Modified Last Commit
lp:ubuntu/edgy/gnupg 1 Development 2009-12-02 23:27:46 UTC
10. * SECURITY UPDATE: Local arbitrary co...

Author: Martin Pitt
Revision Date: 2006-08-03 08:11:46 UTC

* SECURITY UPDATE: Local arbitrary code execution.
* Add debian/patches/27_comment_control_overflow.dpatch:
  - Fix buffer overflows in parse_comment() and parse_gpg_control().
  - Patch extracted from stable 1.4.5 release.
  - Reproducer:
    perl -e 'print "\xfd\xff\xff\xff\xff\xfe"'| gpg --no-armor
  - Credit: Evgeny Legerov
  - CVE-2006-3746

lp:ubuntu/edgy-security/gnupg 1 Development 2009-12-02 23:27:59 UTC
13. * SECURITY UPDATE: without --status-f...

Author: Kees Cook
Revision Date: 2007-03-07 14:10:02 UTC

* SECURITY UPDATE: without --status-fd, forged inline sigs can appear valid.
* debian/patches/50_stop_multiple_messages.dpatch: ported upstream patch.
* References
  ftp://ftp.gnupg.org/gcrypt/gnupg/patches/gnupg-1.4.6-multiple-message.patch
  CVE-2007-1263

lp:ubuntu/edgy-updates/gnupg 1 Development 2009-12-02 23:28:20 UTC
13. * SECURITY UPDATE: without --status-f...

Author: Kees Cook
Revision Date: 2007-03-07 14:10:02 UTC

* SECURITY UPDATE: without --status-fd, forged inline sigs can appear valid.
* debian/patches/50_stop_multiple_messages.dpatch: ported upstream patch.
* References
  ftp://ftp.gnupg.org/gcrypt/gnupg/patches/gnupg-1.4.6-multiple-message.patch
  CVE-2007-1263

13 of 3 results