Hi.

Two questions:

1) Are we sure that this only affected gnupg 2.0.14? Werner does not mention concretely whether versions before are affected or not (http://marc.info/?l=gnupg-users&m=126451730710129&w=2).
When entered 2.0.14 testing, and do we need to release a DSA?

Has the security team being noticed about this issue? Should we do so now?


2) According to the BTS, the bug was filed on the 1st of February, few days after reported by Werner. How could it happen, that it take such tremendously long to fix that in the Debian Package? Nearly 4 months!!

Give that this bug is highly critical and given the special security sensitive nature of packages like gnupg,... I guess we need something to better track this.


Last but not least:
For users that used the affected versions,... it's really hard to notice that there was a problem at all (not everybody reads the changelogs)...
Can we do anything here?


(perhaps this needs to be reopened for the above issues)

Cheers,
Chris.

----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.




--
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to