Testing requested: gnupg 1.4.10-4+squeeze5

2014-09-11 Thread Matt Palmer
Hi everyone, I've prepared an upload for LTS to fix the following issues: * Avoid infinite loop in incompressing garbled packets. * Fix for CVE-2014-5270: side-channel attacks on Elgamal encryption subkeys. * Filter responses from keyservers to ensure that only keys that were reques

Re: CVE-2014-0205 and CVE-2014-3535

2014-09-11 Thread Ben Hutchings
[Adding debian-lts public list] On Thu, 2014-09-11 at 12:23 +0200, Moritz Mühlenhoff wrote: > On Thu, Sep 11, 2014 at 07:37:13AM +0200, Salvatore Bonaccorso wrote: > > Hi Ben, > > > > On Thu, Sep 11, 2014 at 06:51:54AM +0200, Salvatore Bonaccorso wrote: > > > Hi Ben, > > > > > > On Thu, Sep 11,

Re: Report about the work of contributors paid by Freexian

2014-09-11 Thread Raphael Hertzog
Hi, some updates: On Wed, 10 Sep 2014, Raphael Hertzog wrote: > * Holger Levsen: [48]July / [49]August > 49. http://layer-acht.org/thinking/blog/20140819-lts-august-2014/ This moved to http://layer-acht.org/thinking/blog/20140909-lts-august-2014/ since I posted the article... >To hav