[SECURITY] Fedora Core 4 Test Update: gnupg-1.4.5-1

Nalin Dahyabhai nalin at redhat.com
Tue Aug 1 18:47:46 UTC 2006


---------------------------------------------------------------------
Fedora Test Update Notification
FEDORA-2006-867
2006-08-01
---------------------------------------------------------------------

Product     : Fedora Core 4
Name        : gnupg
Version     : 1.4.5
Release     : 1
Summary     : A GNU utility for secure communication and data storage.
Description :
GnuPG (GNU Privacy Guard) is a GNU utility for encrypting data and
creating digital signatures. GnuPG has advanced key management
capabilities and is compliant with the proposed OpenPGP Internet
standard described in RFC2440. Since GnuPG doesn't use any patented
algorithm, it is not compatible with any version of PGP2 (PGP2.x uses
only IDEA for symmetric-key encryption, which is patented worldwide).

---------------------------------------------------------------------
Update Information:

This update upgrades GnuPG to version 1.4.5 to correct
errors in the parsing of certain types of packets.  Absent
new bug reports, it will be moved from testing to final on
or around 2 August 2006.
---------------------------------------------------------------------
* Tue Aug  1 2006 Nalin Dahyabhai <nalin at redhat.com> - 1.4.5-1
- update to 1.4.5, fixing additional size overflows in packet parsing (#200904,
  CVE-2006-3746)
- temporarily disable curl support again
* Fri Jul 28 2006 Nalin Dahyabhai <nalin at redhat.com> - 1.4.4.90-1
- update to 1.4.5rc1 to check for build problems, but mark it as 1.4.4.90
  to avoid looking "newer" than the eventual 1.4.5
- because we call aclocal, buildrequire gettext-devel to get AM_GNU_GETTEXT
* Thu Jul 20 2006 Nalin Dahyabhai <nalin at redhat.com> - 1.4.4-7
- add BuildPrereq on curl-devel to get curl's ipv6 support (#198375)
* Wed Jul 12 2006 Nalin Dahyabhai <nalin at redhat.com> - 1.4.4-6
- fix a cast in gpgkeys_hkp to avoid tripping stack smashing or buffer overflow
  detection (#198612)
* Wed Jul 12 2006 Jesse Keating <jkeating at redhat.com> - 1.4.4-5.1
- rebuild
* Wed Jul  5 2006 Nalin Dahyabhai <nalin at redhat.com> - 1.4.4-5
- try again using per-platform buildprereq (jkeating)
* Wed Jul  5 2006 Nalin Dahyabhai <nalin at redhat.com> - 1.4.4-4
- buildprereq libusb-devel, so that we get CCID support back (#197450)

---------------------------------------------------------------------
This update can be downloaded from:
    http://download.fedora.redhat.com/pub/fedora/linux/core/updates/testing/4/

b911131a9c4fe466379549a9980f9fb7f573fe5a  SRPMS/gnupg-1.4.5-1.src.rpm
b911131a9c4fe466379549a9980f9fb7f573fe5a  noarch/gnupg-1.4.5-1.src.rpm
30bbc1c04923578801dfcdf3ba43d88bfd0f816b  ppc/gnupg-1.4.5-1.ppc.rpm
3fd15ce18ab9de6ed0da22132ab45c9ebcf405fb  ppc/debug/gnupg-debuginfo-1.4.5-1.ppc.rpm
f2a7789c589b29346e2e3cf0e3e658435a75ba64  x86_64/gnupg-1.4.5-1.x86_64.rpm
724e619aef217819f95bfe9e5074553e317ab4d0  x86_64/debug/gnupg-debuginfo-1.4.5-1.x86_64.rpm
1bec676c9d27abafe07034dd737f9e2a04846f9e  i386/gnupg-1.4.5-1.i386.rpm
f9f7f4402c6baa2b1872b825181f1e9924574c07  i386/debug/gnupg-debuginfo-1.4.5-1.i386.rpm

This update can be installed with the 'yum' update program.  Use 'yum update
package-name' at the command line.  For more information, refer to 'Managing
Software with yum,' available at http://fedora.redhat.com/docs/yum/.
---------------------------------------------------------------------




More information about the test mailing list