Re: #100409 GnuPG printf format string vulnerability

2001-06-11 Thread Florian Weimer
Wichert Akkerman <[EMAIL PROTECTED]> writes: > Previously Florian Weimer wrote: > > With GnuPG 1.0.4, the web of trust can be compromised by an attacker, > > How? GnuPG 1.0.4 automatically assigns ultimate trust to public keys if a corresponding private key is present in the private key ring. W

Re: #100409 GnuPG printf format string vulnerability

2001-06-11 Thread Wichert Akkerman
Previously Florian Weimer wrote: > With GnuPG 1.0.4, the web of trust can be compromised by an attacker, How? > and there's a pretty severe problem with detached signature > verification. That was fixed months ago, check the changelog. Wichert. -- __

Re: #100409 GnuPG printf format string vulnerability

2001-06-11 Thread Florian Weimer
Wichert Akkerman <[EMAIL PROTECTED]> writes: > Previously Florian Weimer wrote: > > With GnuPG 1.0.4, the web of trust can be compromised by an attacker, > > How? GnuPG 1.0.4 automatically assigns ultimate trust to public keys if a corresponding private key is present in the private key ring.

Re: #100409 GnuPG printf format string vulnerability

2001-06-11 Thread Florian Weimer
Wouter Cloetens <[EMAIL PROTECTED]> writes: > Extra details on the bug report for gnupg-1.04-2 can be found > on http://www.securityfocus.com/bid/2797. Most distributions > appear to have reported a security alert, but all recommend > upgrading to 1.0.6. A backport for stable is in order, I > gue

Re: #100409 GnuPG printf format string vulnerability

2001-06-11 Thread Wichert Akkerman
Previously Florian Weimer wrote: > With GnuPG 1.0.4, the web of trust can be compromised by an attacker, How? > and there's a pretty severe problem with detached signature > verification. That was fixed months ago, check the changelog. Wichert. -- _

Re: #100409 GnuPG printf format string vulnerability

2001-06-11 Thread Florian Weimer
Wouter Cloetens <[EMAIL PROTECTED]> writes: > Extra details on the bug report for gnupg-1.04-2 can be found > on http://www.securityfocus.com/bid/2797. Most distributions > appear to have reported a security alert, but all recommend > upgrading to 1.0.6. A backport for stable is in order, I > gu

Re: #100409 GnuPG printf format string vulnerability

2001-06-10 Thread Wichert Akkerman
Previously Wouter Cloetens wrote: > Extra details on the bug report for gnupg-1.04-2 can be found > on http://www.securityfocus.com/bid/2797. Most distributions > appear to have reported a security alert, but all recommend > upgrading to 1.0.6. A backport for stable is in order, It's being worked

#100409 GnuPG printf format string vulnerability

2001-06-10 Thread Wouter Cloetens
Extra details on the bug report for gnupg-1.04-2 can be found on http://www.securityfocus.com/bid/2797. Most distributions appear to have reported a security alert, but all recommend upgrading to 1.0.6. A backport for stable is in order, I guess... bfn, Wouter From: Ulrik De Bie <[EMAIL PROTECT

Re: #100409 GnuPG printf format string vulnerability

2001-06-10 Thread Wichert Akkerman
Previously Wouter Cloetens wrote: > Extra details on the bug report for gnupg-1.04-2 can be found > on http://www.securityfocus.com/bid/2797. Most distributions > appear to have reported a security alert, but all recommend > upgrading to 1.0.6. A backport for stable is in order, It's being worke

#100409 GnuPG printf format string vulnerability

2001-06-10 Thread Wouter Cloetens
Extra details on the bug report for gnupg-1.04-2 can be found on http://www.securityfocus.com/bid/2797. Most distributions appear to have reported a security alert, but all recommend upgrading to 1.0.6. A backport for stable is in order, I guess... bfn, Wouter From: Ulrik De Bie <[EMAIL PROTEC