Bug#695932: deb822: flawed handling of signed data

2014-08-26 Thread John Wright
On Wed, Aug 27, 2014 at 01:36:33AM +0200, Ansgar Burchardt wrote: > Control: tag -1 - moreinfo unreproducible > > John Wright writes: > > On Fri, Dec 14, 2012 at 02:31:03PM +, Ansgar Burchardt wrote: > >> Package: python-debian > >> Version: 0.1.21+nmu2 > >> Severity: important > >> > >> deb

Bug#695932: deb822: flawed handling of signed data

2014-08-26 Thread Ansgar Burchardt
Control: tag -1 - moreinfo unreproducible John Wright writes: > On Fri, Dec 14, 2012 at 02:31:03PM +, Ansgar Burchardt wrote: >> Package: python-debian >> Version: 0.1.21+nmu2 >> Severity: important >> >> debian.deb822 does not handle signed data properly and can be tricked into >> processin

Bug#695932: deb822: flawed handling of signed data

2014-08-26 Thread John Wright
package python-debian tags 695932 moreinfo unreproducible thanks On Fri, Dec 14, 2012 at 02:31:03PM +, Ansgar Burchardt wrote: > Package: python-debian > Version: 0.1.21+nmu2 > Severity: important > > debian.deb822 does not handle signed data properly and can be tricked into > processing unsi

Bug#695932: deb822: flawed handling of signed data

2012-12-14 Thread Ansgar Burchardt
Package: python-debian Version: 0.1.21+nmu2 Severity: important debian.deb822 does not handle signed data properly and can be tricked into processing unsigned data while thinking the data is signed. I have attached an example program and *.dsc demonstrating the problem: it will output "gnupg", bu