Subject: CVS commit: pkgsrc/security/gnupg
From: Thomas Klausner
Date: 2015-02-28 01:13:25
Message id: 20150228001325.ED12B98@cvs.netbsd.org

Log Message:
Update to 1.4.19:

Noteworthy changes in version 1.4.19 (2015-02-27)
-------------------------------------------------

 * Use ciphertext blinding for Elgamal decryption [CVE-2014-3591].
   See http://www.cs.tau.ac.il/~tromer/radioexp/ for details.

 * Fixed data-dependent timing variations in modular exponentiation
   [related to CVE-2015-0837, Last-Level Cache Side-Channel Attacks
   are Practical].

 * Detect faulty use of --verify on detached signatures.

 * Changed the PKA method to use CERT records and hashed names.

 * New import option "keep-ownertrust".

 * Support algorithm names when generating keys using the --command-fd
   method.

 * Updated many translations.

 * Updated build system.

 * Fixed a regression in keyserver import

 * Fixed argument parsing for option --debug-level.

 * Fixed DoS based on bogus and overlong key packets.

 * Fixed bugs related to bogus keyrings.

 * The usual minor minor bug fixes.

Files:
RevisionActionfile
1.128modifypkgsrc/security/gnupg/Makefile
1.28modifypkgsrc/security/gnupg/PLIST
1.66modifypkgsrc/security/gnupg/distinfo