Bug#697251: gnupg2: gnupg key import memory corruption

2013-01-07 Thread Eric Dorland
* Thijs Kinkhorst (th...@debian.org) wrote: > On Sun, January 6, 2013 06:38, Eric Dorland wrote: > > Gah. I went out of town for Saturday and Sunday. I meant to upload before > > I left today but forgot. I just tried to now but I can't seem to reach my > > main Debian machine. So I won't be able to

Bug#697251: gnupg2: gnupg key import memory corruption

2013-01-06 Thread Thijs Kinkhorst
On Sun, January 6, 2013 06:38, Eric Dorland wrote: > Gah. I went out of town for Saturday and Sunday. I meant to upload before > I left today but forgot. I just tried to now but I can't seem to reach my > main Debian machine. So I won't be able to upload before Sunday night > Eastern USA time. So i

Bug#697251: gnupg2: gnupg key import memory corruption

2013-01-05 Thread Eric Dorland
Gah. I went out of town for Saturday and Sunday. I meant to upload before I left today but forgot. I just tried to now but I can't seem to reach my main Debian machine. So I won't be able to upload before Sunday night Eastern USA time. So if anyone wants to build it from the diff and upload feel

Bug#697251: gnupg2: gnupg key import memory corruption

2013-01-05 Thread Nico Golde
Hi, * Eric Dorland [2013-01-05 14:02]: > * Thijs Kinkhorst (th...@debian.org) wrote: > > On Fri, January 4, 2013 11:39, Thijs Kinkhorst wrote: > > > On Thu, January 3, 2013 04:19, Christoph Anton Mitterer wrote: > > >> This is a follow up for #697108 and CVE-2012-6085. > > > > > > Eric, > > > > >

Bug#697251: gnupg2: gnupg key import memory corruption

2013-01-05 Thread Thijs Kinkhorst
Hi Eric, On Sat, January 5, 2013 08:30, Eric Dorland wrote: > * Thijs Kinkhorst (th...@debian.org) wrote: >> On Fri, January 4, 2013 11:39, Thijs Kinkhorst wrote: >> > On Thu, January 3, 2013 04:19, Christoph Anton Mitterer wrote: >> >> This is a follow up for #697108 and CVE-2012-6085. >> > >> >

Bug#697251: gnupg2: gnupg key import memory corruption

2013-01-04 Thread Eric Dorland
* Thijs Kinkhorst (th...@debian.org) wrote: > On Thu, January 3, 2013 04:19, Christoph Anton Mitterer wrote: > > This is a follow up for #697108 and CVE-2012-6085. > > Eric, > > Thanks for fixing this in unstable. Can you also provide an update for > stable-security? Let me know if you prefer tha

Bug#697251: gnupg2: gnupg key import memory corruption

2013-01-04 Thread Thijs Kinkhorst
On Fri, January 4, 2013 11:39, Thijs Kinkhorst wrote: > On Thu, January 3, 2013 04:19, Christoph Anton Mitterer wrote: >> This is a follow up for #697108 and CVE-2012-6085. > > Eric, > > Thanks for fixing this in unstable. Can you also provide an update for > stable-security? Let me know if you pre

Bug#697251: gnupg2: gnupg key import memory corruption

2013-01-04 Thread Thijs Kinkhorst
On Thu, January 3, 2013 04:19, Christoph Anton Mitterer wrote: > This is a follow up for #697108 and CVE-2012-6085. Eric, Thanks for fixing this in unstable. Can you also provide an update for stable-security? Let me know if you prefer that we handle it. Cheers, Thijs -- To UNSUBSCRIBE, email

Bug#697251: gnupg2: gnupg key import memory corruption

2013-01-03 Thread Eric Dorland
Thanks for the heads up. Will get to it later today. * Christoph Anton Mitterer (cales...@scientia.net) wrote: > btw: The corresponding redhat bug[0] seems to already contain some > backported patches till 2.0.20 comes out. > > > [0] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-6085 -

Bug#697251: gnupg2: gnupg key import memory corruption

2013-01-02 Thread Christoph Anton Mitterer
btw: The corresponding redhat bug[0] seems to already contain some backported patches till 2.0.20 comes out. [0] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-6085 smime.p7s Description: S/MIME cryptographic signature

Bug#697251: gnupg2: gnupg key import memory corruption

2013-01-02 Thread Christoph Anton Mitterer
Package: gnupg2 Version: 2.0.19-1 Severity: critical Tags: security Justification: root security hole Hi. This is a follow up for #697108 and CVE-2012-6085. While it seems that all world fixes this only for gpg 1.4.x Werner's bug entry[0,1] implies that 2.x is also affected. Could you please ha