07-11-05 10:47 PM
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
["Followup-To:" header set to alt.privacy.anon-server.]
On Mon, 11 Jul 2005 16:32:25 +0200, Thomas J. Boschloo wrote in
Message-Id: <42d282d2$0$11989$e4fe514c@news.xs4all.nl>:
> I guess they could also consider shutting down and appling the (ZLib
> 1.2.3??) patch before decrypting any new traffic waiting in the pools.
Hi Thomas,
There is no released patch for this bug as yet. As a serious security
fix, no doubt it will make it's way out to *nix packages very rapidly
once one is available.
> This bug is serious guys..
Yes, but so far as I can tell, not life threatening.
As I understand it, the bug could cause an application to crash by
overwriting and corrupting memory. This is serious, but from the
perspective of Gnupg and Remailers it's not going to decode messages and
email passphrases to the FBI. The danger level is not sufficient to
warrent the immediate shutting down of services IMO. Hopefully things
will hang together until a patch is available.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)
iQEVAwUBQtKGr2oLu9HNUqmMAQrN2QgAkotoSnF2
XxKPnDiUQ07dBQEedda2BjIA
0h4tXPxIAVZym5CZHRSZdQBhKII7YT/EiEnSTeUBgo/iecCn7sir3V6Rk7NGeRMv
vnZcf4rML19rFMC/Kt5sBsKWUKeER6lD/IxxrVUmEpTjXeI0QXRqsVBVEGDAtiLn
yjTsOv13HQbuvNkfoy/ lfJAISTz5lAuPPbZM4gYd+wJcGtPqma1RTa21kJf
kLeum
9Yyhn3nmkDqRrDF950ymC8MnTWafVYz61HBjNvvI
KfnichR0Lkmbn0LgV+CvQZal
6d8iYvvdLDZN7WAJuCX650zXK4L90HRmMdqqi3d8
e030HPDJXZzRTQ==
=RMOR
-----END PGP SIGNATURE-----
--
pub 1024D/8ED57743 2003-07-08 Bananasplit Operator
Key fingerprint = 796F 67E0 E890 A0BB BDAE EBB4 94A6 7A09 8ED5 7743
uid Admin <admin.bananasplit.info>
[ Post a follow-up to this message ]
|