[prev in list] [next in list] [prev in thread] [next in thread] 

List:       gpg4win-devel
Subject:    [Gpg4win-devel] =?utf-8?q?=5Bgpg4win-Bugs=5D=5B1241=5D_=22vulnera?=
From:       <gpg4win-bugs () wald ! intevation ! org>
Date:       2010-01-13 12:53:37
Message-ID: 20100113125337.2735186607DD () pyrosoma ! intevation ! org
[Download RAW message or body]

Bugs item #1241, was opened at 2010-01-13 13:53
Status: Open
Priority: 3
Submitted By: Olav Seyfarth (nursoda)
Assigned to: Nobody (None)
Summary: "vulnerable" GTK should be updated 
Resolution: None
Severity: normal
Version: 2.0.1
Component: None
Operating System: Windows XP
Product: gpg4win exe-Installer
Hardware: PC
URL: 


Initial Comment:
Using Secunias Personal Software Inspector in Expert mode, it shows C:\Program \
Files\GNU\GnuPG\libgdk-win32-2.0-0.dll be vulnerable and proposes to install a newer \
GTK+ release. Doing so renders GnuPG unusable.

While the bug itself is classified "not critical" by Secunia \
(http://secunia.com/advisories/37852/), a security component such as GPG4Win should \
not contain parts that have known weaknesses.

Thus I propose to release an updated GPG4Win version that includes patched GTK+ \
libraries.

----------------------------------------------------------------------

You can respond by visiting: 
http://wald.intevation.org/tracker/?func=detail&atid=126&aid=1241&group_id=11
_______________________________________________
Gpg4win-devel mailing list
Gpg4win-devel@wald.intevation.org
http://lists.wald.intevation.org/mailman/listinfo/gpg4win-devel


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic