Hi all,

for those of you who haven't seen it yet, I thought this article (slashdot) 
was important to many of us...

 WeLikeRoy writes "A serious problem in the use of GPG to verify digital 
signatures has been discovered, which also affects the use of gpg in email. 
It is possible for an attacker to take any signed message and inject extra 
arbitrary data without affecting the signed status of the message. Depending 
on how gpg is invoked, it may be possible to output just faked data as 
several variants of this attack have been discovered. All versions of gnupg 
prior to 1.4.2.2 are affected, and it is thus recommended to update GnuPG as 
soon as possible to version 1.4.2.2."

http://it.slashdot.org/it/06/03/09/233227.shtml

Nick

_______________________________________________
clug-talk mailing list
[email protected]
http://clug.ca/mailman/listinfo/clug-talk_clug.ca
Mailing List Guidelines (http://clug.ca/ml_guidelines.php)
**Please remove these lines when replying

Reply via email to