Hi.
Two questions:
1) Are we sure that this only affected gnupg 2.0.14? Werner does not
mention concretely whether versions before are affected or not
(http://marc.info/?l=gnupg-users&m=126451730710129&w=2).
When entered 2.0.14 testing, and do we need to release a DSA?
Has the security team being noticed about this issue? Should we do so now?
2) According to the BTS, the bug was filed on the 1st of February, few
days after reported by Werner.
How could it happen, that it take such tremendously long to fix that
in the Debian Package? Nearly 4 months!!
Give that this bug is highly critical and given the special security
sensitive nature of packages like gnupg,... I guess we need something
to better track this.
Last but not least:
For users that used the affected versions,... it's really hard to
notice that there was a problem at all (not everybody reads the
changelogs)...
Can we do anything here?
(perhaps this needs to be reopened for the above issues)
Cheers,
Chris.
----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.
--
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]