[ubuntu/saucy-proposed] gnupg2 2.0.20-1ubuntu3 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Tue Oct 8 15:39:20 UTC 2013


gnupg2 (2.0.20-1ubuntu3) saucy; urgency=low

  * SECURITY UPDATE: incorrect no-usage-permitted flag handling
    - debian/patches/CVE-2013-4351.patch: correctly handle empty key flags
      in g10/getkey.c, g10/keygen.c, include/cipher.h.
    - CVE-2013-4351
  * SECURITY UPDATE: denial of service via infinite recursion
    - debian/patches/CVE-2013-4402.patch: set limits on number of filters
      and nested packets in common/iobuf.c, g10/mainproc.c.
    - CVE-2013-4402

Date: Mon, 07 Oct 2013 15:38:03 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/saucy/+source/gnupg2/2.0.20-1ubuntu3
-------------- next part --------------
Format: 1.8
Date: Mon, 07 Oct 2013 15:38:03 -0400
Source: gnupg2
Binary: gnupg-agent scdaemon gpgsm gnupg2
Architecture: source
Version: 2.0.20-1ubuntu3
Distribution: saucy
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 gnupg-agent - GNU privacy guard - password agent
 gnupg2     - GNU privacy guard - a free PGP replacement (new v2.x)
 gpgsm      - GNU privacy guard - S/MIME version
 scdaemon   - GNU privacy guard - smart card support
Changes: 
 gnupg2 (2.0.20-1ubuntu3) saucy; urgency=low
 .
   * SECURITY UPDATE: incorrect no-usage-permitted flag handling
     - debian/patches/CVE-2013-4351.patch: correctly handle empty key flags
       in g10/getkey.c, g10/keygen.c, include/cipher.h.
     - CVE-2013-4351
   * SECURITY UPDATE: denial of service via infinite recursion
     - debian/patches/CVE-2013-4402.patch: set limits on number of filters
       and nested packets in common/iobuf.c, g10/mainproc.c.
     - CVE-2013-4402
Checksums-Sha1: 
 8e2345a3914086dad6eeaf0f9747e69bef6d873c 2323 gnupg2_2.0.20-1ubuntu3.dsc
 9d9cb1fd7c72e80125e8c60becae24bc81a9892e 20615 gnupg2_2.0.20-1ubuntu3.debian.tar.bz2
Checksums-Sha256: 
 4ded527639129d2027d9225a5a384802ab7c83f0fc5d21db9c30a36a93c55766 2323 gnupg2_2.0.20-1ubuntu3.dsc
 27ef8dcf8372957b29295c7af5d9c0b67c03ddb3be9e2881503ea680746d3160 20615 gnupg2_2.0.20-1ubuntu3.debian.tar.bz2
Files: 
 36ec900e92c4be998144652fd6dc6630 2323 utils optional gnupg2_2.0.20-1ubuntu3.dsc
 581b9ea05d70d05f96e446f3645c2bd7 20615 utils optional gnupg2_2.0.20-1ubuntu3.debian.tar.bz2
Original-Maintainer: Eric Dorland <eric at debian.org>


More information about the Saucy-changes mailing list