Debian Security Advisory: New version of gnupg installed

Nov 13, 2000, 20:50 (0 Talkback[s])

Package: gnupg
Debian-specific: no

The version of gnupg that was distributed in Debian GNU/Linux 2.2 had a logic error in the code that checks for valid signatures which could cause false positive results: Jim Small discovered that if the input contained multiple signed sections the exit-code gnupg returned was only valid for the last section, so improperly signed other sections were not noticed.

This has been fixed in version 1.0.4-1 and we recommend that you upgrade your gnupg package to that version. Please note that this version of gnupg includes the RSA code directly instead of relying on the gpg-rsa package. This means that the "load-extension rsa" command in ~/.gnupg/options is no longer needed and must be removed: gnupg will not work correctly if it tries to load an extension that is not present.

Debian GNU/Linux 2.2 alias potato

Potato was released for the alpha, arm, i386, m68k, powerpc and sparc architectures.

