Hi, I have released ftp://ftp.gnupg.org/gcrypt/gnupg/gnupg-1.4.2.1.tar.bz2 ftp://ftp.gnupg.org/gcrypt/gnupg/gnupg-1.4.2.1.tar.bz2.sig or ftp://ftp.gnupg.org/gcrypt/gnupg/gnupg-1.4.2-1.4.2.1.diff.bz2 This fixes the reported problem. I will write an advisory tomorrow. Its a bit late now and thus I give the mirrors ime to catch up ;-) Noteworthy changes in version 1.4.2.1 (2006-02-14) -------------------------------------------------- * Security fix for a verification weakness in gpgv. Some input could lead to gpgv exiting with 0 even if the detached signature file did not carry any signature. This is not as fatal as it might seem because the suggestion as always been not to rely on th exit code but to parse the --status-fd messages. However it is likely that gpgv is used in that simplified way and thus we do this release. Same problem with "gpg --verify" but nobody should have used this for signature verification without checking the status codes anyway. Thanks to the taviso from Gentoo for reporting this problem. [David: I also released 1.4.3rc1 on alpha/gnupg.] Shalom-Salam, Werner
Attachment:
pgpLZI6qq5mlD.pgp
Description: PGP signature