-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Then it will be fixed when I get 1.7.4 packaged and uploaded. Right now I'm under a deadline at work and paycheck trumps volunteering. I'll get it up as soon as possible though.
Matthias Klose wrote: > Package: paramiko > Version: 1.7.3-1 > Severity: serious > Tags: security, patch > > See http://www.lag.net/pipermail/paramiko/2008-April/000678.html > > "Revision #486 [1] (and therefore Paramiko 1.7.3) re-introduces the > problems associated with PyCrypto's RandomPool class that I described > in my post back in January. RandomPool is not a simple "get random > bits" primitive, but paramiko is again using it as one." > > Patch at http://www.lag.net/pipermail/paramiko/2008-April/000679.html > > This is fixed in the new upstream 1.7.4 as well. > > -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org iF0EARECAB0FAkh8zd8WGGhrcDovL3N1YmtleXMucGdwLm5ldAAKCRBALeRNdPfm QJwxAJ9wavCmwyp+pg9yT2jkWqDiQEXCKgCgt36XRaV7SLPtOhTCPiyyJIC2aZo= =6dQ+ -----END PGP SIGNATURE----- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]