[ubuntu/precise-security] gnupg2 2.0.17-2ubuntu2.12.04.6 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Wed Apr 1 13:17:19 UTC 2015
gnupg2 (2.0.17-2ubuntu2.12.04.6) precise-security; urgency=medium
* Screen responses from keyservers (LP: #1409117)
- d/p/0001-Screen-keyserver-responses.patch
- d/p/0002-Make-screening-of-keyserver-result-work-with-multi-k.patch
- d/p/0003-Add-kbnode_t-for-easier-backporting.patch
- d/p/0004-gpg-Fix-regression-due-to-the-keyserver-import-filte.patch
* Fix large key size regression from CVE-2014-5270 changes (LP: #1371766)
- d/p/Add-build-and-runtime-support-for-larger-RSA-key.patch
- debian/rules: build with --enable-large-secmem
* SECURITY UPDATE: invalid memory read via invalid keyring
- debian/patches/CVE-2015-1606.patch: skip all packets not allowed in
a keyring in g10/keyring.c.
- CVE-2015-1606
* SECURITY UPDATE: memcpy with overlapping ranges
- debian/patches/CVE-2015-1607.patch: use inline functions to convert
buffer data to scalars in common/iobuf.c, g10/build-packet.c,
g10/getkey.c, g10/keygen.c, g10/keyid.c, g10/main.h, g10/misc.c,
g10/parse-packet.c, g10/tdbio.c, g10/trustdb.c, include/host2net.h,
kbx/keybox-dump.c, kbx/keybox-openpgp.c, kbx/keybox-search.c,
kbx/keybox-update.c, scd/apdu.c, scd/app-openpgp.c,
scd/ccid-driver.c, scd/pcsc-wrapper.c, tools/ccidmon.c.
- CVE-2015-1607
Date: 2015-03-27 12:33:25.457836+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/gnupg2/2.0.17-2ubuntu2.12.04.6
-------------- next part --------------
Sorry, changesfile not available.
More information about the Precise-changes
mailing list