[Secure-testing-commits] r611 - sarge-checks/CAN

Moritz Muehlenhoff jmm-guest@costa.debian.org
Tue, 22 Mar 2005 11:32:18 +0100


Author: jmm-guest
Date: 2005-03-22 11:32:15 +0100 (Tue, 22 Mar 2005)
New Revision: 611

Modified:
   sarge-checks/CAN/list
Log:
OpenPGP is a standard, and not to be confused with the commercial
product PGP. gnupg implements the OpenPGP standard and is affected
by this (minor) cryptographic issue. I'll file a bug later on.


Modified: sarge-checks/CAN/list
===================================================================
--- sarge-checks/CAN/list	2005-03-22 08:44:18 UTC (rev 610)
+++ sarge-checks/CAN/list	2005-03-22 10:32:15 UTC (rev 611)
@@ -1689,7 +1689,7 @@
 CAN-2005-0367 (Multiple directory traversal vulnerabilities in ArGoSoft Mail Server ...)
 	NOTE: not-for-us (ArGoSoft Mail Server)
 CAN-2005-0366 (The integrity check feature in OpenPGP, when handling a message that ...)
-	NOTE: not-for-us (openpgp)
+	gnupg (unfixed)
 CAN-2005-0364 (Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and ...)
 	NOTE: not-for-us (bind on hp-ux)
 CAN-2005-0361