Jeremie Courreges-Anglas <[email protected]> writes: > CVSROOT: /cvs > Module name: ports > Changes by: [email protected] 2013/11/16 13:29:00 > > Modified files: > security/gnupg : Makefile distinfo > Removed files: > security/gnupg/patches: patch-mpi_mpi-pow_c > > Log message:
Should read: > SECURITY update to gnupg-1.4.15, fixes CVE-2013-4402 (infinite recursion > parsing compressed packets) and includes the patch we had for > CVE-2013-4242 (Yarom/Falkner flush+reload side-channel attack on RSA > secret keys). Input from and ok sthen@ -- jca | PGP : 0x06A11494 / 61DB D9A0 00A4 67CF 2A90 8961 6191 8FBF 06A1 1494
