Fixed in all branches but there is no potential for exploiting. See also gnupg-devel@ ML.
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Feed All Stories
All Stories
All Stories
May 26 2025
May 26 2025
• werner closed T7662: GPG's uncompress_ecc_q_in_canon_sexp reads past a constant string into rodata as Resolved.
• werner edited projects for T7663: Certificated signed using SHA-1 isn't trusted, but needs --force-sign-key to re-sign., added: Feature Request, gnupg26, gnupg24; removed Bug Report.
• werner triaged T7663: Certificated signed using SHA-1 isn't trusted, but needs --force-sign-key to re-sign. as Low priority.
This should do the trick (master) but have not yet tested it:
• ikloecker committed rMTP430e80104af3: Add translations used for Gpg4win 4.4.1 (authored by • ikloecker).
Add translations used for Gpg4win 4.4.1
• ikloecker committed rKLEOPATRA1aa33a7bb950: Add translations used for Gpg4win 4.4.1 (authored by • ikloecker).
Add translations used for Gpg4win 4.4.1
• ikloecker committed rLIBKLEOcacbddd9b390: Add translations used for Gpg4win 4.4.1 (authored by • ikloecker).
Add translations used for Gpg4win 4.4.1
• ikloecker committed rKLEOPATRAdfdbab94165d: Make use of new CreationFlags and new QuickJob API (authored by • ikloecker).
Make use of new CreationFlags and new QuickJob API
• ikloecker committed rKLEOPATRAf7da5917822f: Allow customization of full version info shown in About window (authored by • ikloecker).
Allow customization of full version info shown in About window
• ikloecker committed rKLEOPATRA8323f1bb01c1: Remove customization of RELEASE_SERVICE_VERSION (authored by • ikloecker).
Remove customization of RELEASE_SERVICE_VERSION
Fixed. Thanks for the report!
• ikloecker committed rGPGMEPP67abbf811080: Fix wrong definition of operator<<(std::ostream &, const Error &) (authored by • ikloecker).
Fix wrong definition of operator<<(std::ostream &, const Error &)
CarlSchwan committed rW0c7129e857eb: Backport gpgmepp/qgpgme patches for reencrypt feature (authored by CarlSchwan).
Backport gpgmepp/qgpgme patches for reencrypt feature
The classic NIST P521 pitfall ;-)
• ikloecker committed rGPGMEQT7e8932469e1d: Sort includes and macro invocations alphabetically (authored by • ikloecker).
Sort includes and macro invocations alphabetically
• ikloecker committed rGPGMEQT433e40765dfc: Explicitly define constructor and destructor of some Job classes (authored by • ikloecker).
Explicitly define constructor and destructor of some Job classes
Add d-pointer to Job class
doc: Update NEWS
• gniibe changed the status of T5964: gnupg should use the KDFs implemented in libgcrypt, a subtask of T6191: FIPS: Supporting running FIPS enabled machine, from Open to Testing.
• gniibe changed the status of T5964: gnupg should use the KDFs implemented in libgcrypt from Open to Testing.
• gniibe committed rG0c7e7ec0c846: gpg: Fix ECC_POINT_LEN_MAX to allow NIST curves. (authored by • gniibe).
gpg: Fix ECC_POINT_LEN_MAX to allow NIST curves.
• gniibe added a comment to T7664: tests/openpgp/ecc.scm fails when building GPG with address sanitizer.
Thank you.
l10n daemon script <scripty@kde.org> committed rKLEOPATRA7af8cd7655d6: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 25 2025
May 25 2025
l10n daemon script <scripty@kde.org> committed rMTPa7ce69842629: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed rLIBKLEO2e09d1a7bbdd: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed rKLEOPATRA2f3d1032ca11: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed rKLEOPATRA7529ce94d597: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
l10n daemon script <scripty@kde.org> committed rMTP94ea410afd87: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed rLIBKLEO3e967b1e3248: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed rKLEOPATRA0bef69972bd0: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed rKLEOPATRAcfdcccdfdf41: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
ukleinek added a comment to T7663: Certificated signed using SHA-1 isn't trusted, but needs --force-sign-key to re-sign..
Maybe related:
May 24 2025
May 24 2025
• werner committed rGf3dfbe3fcdc0: common: Fix read buffer over-read in uncompress_ecc_q_in_canon_sexp. (authored by Collin Funk via Gnupg-devel <gnupg-devel@gnupg.org>).
common: Fix read buffer over-read in uncompress_ecc_q_in_canon_sexp.
• werner committed rG14383ff052ff: gpgsm: Make use of the de-vs flag in the trustlist.txt. (authored by • werner).
gpgsm: Make use of the de-vs flag in the trustlist.txt.
• werner committed rG01cb3ba62d77: common: Fix read buffer over-read in uncompress_ecc_q_in_canon_sexp. (authored by Collin Funk via Gnupg-devel <gnupg-devel@gnupg.org>).
common: Fix read buffer over-read in uncompress_ecc_q_in_canon_sexp.
• werner committed rG57c1c96e7f5c: common: Fix read buffer over-read in uncompress_ecc_q_in_canon_sexp. (authored by Collin Funk via Gnupg-devel <gnupg-devel@gnupg.org>).
common: Fix read buffer over-read in uncompress_ecc_q_in_canon_sexp.
Fix an include guard.
l10n daemon script <scripty@kde.org> committed rKLEOPATRA4a54c0f0c558: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Hi Werner, one minor issue in this commit as can be seen by the following GCC warnings:
May 23 2025
May 23 2025
Add testenv start.sh user home tab
Add testdata for sort order
Add testdata for custom word lists
timegrid committed rGPGPASSf55e01a2acd9: Add gpgpass version in testenv start script (authored by timegrid).
Add gpgpass version in testenv start script
timegrid committed rGPGPASS4abefea960ba: Add testdata encrypted for all/valid certs (authored by timegrid).
Add testdata encrypted for all/valid certs
Rename teststore gpgid entries
timegrid committed rGPGPASSddaf99dadecd: Ensure testenv and testuser are valid in start script (authored by timegrid).
Ensure testenv and testuser are valid in start script
timegrid committed rGPGPASS12be127128f6: Use keyids instead of fprs for teststore data (authored by timegrid).
Use keyids instead of fprs for teststore data
timegrid committed rGPGPASS40179bf37fda: Add testdata for symlinks to subfolders of other stores (authored by timegrid).
Add testdata for symlinks to subfolders of other stores
Add empty folders in testdata
Change testenv shortcuts
timegrid committed rGPGPASSd25fbb4f6403: Use custom tmp folder for testdata example outside store root (authored by timegrid).
Use custom tmp folder for testdata example outside store root
Fixes another wrong teststore path
Change to absolute teststore paths
Fixes wrong teststore path
timegrid committed rGPGPASSceaa8f9971d2: Adjust teststore configs to use relative paths (authored by timegrid).
Adjust teststore configs to use relative paths
timegrid committed rGPGPASSe1e99820736e: Add testdata/-envs generation scripts (authored by timegrid).
Add testdata/-envs generation scripts
Adjust teststore template config
json: Fix minor memory leak.
Refactor gpgme-json for future re-use.
was fixed in gpgol 2.5.15
Clean up finished by rG681d75404300: gpg,agent: Clean up around using ECC KEM.
Tested by make check and decrypting tests/openpgp/samplemsgs/pqc-sample-*.enc.asc.
• gniibe committed rG681d75404300: gpg,agent: Clean up around using ECC KEM. (authored by • gniibe).
gpg,agent: Clean up around using ECC KEM.
• gniibe committed rG37bec0df7bf1: common: Fix argument name of gnupg_ecc_kem_kdf. (authored by • gniibe).
common: Fix argument name of gnupg_ecc_kem_kdf.
• gniibe closed T7457: gpg --full-gen-key doesn't show list of keys on card (regression) as Resolved.
• ebo moved T7600: Kleopatra: gpg.exe hangs on trying to exportably certify an already locally signed certificate with multiple UIDs from Restricted Project Column to Restricted Project Column on the Restricted Project board.
• ebo added a project to T7600: Kleopatra: gpg.exe hangs on trying to exportably certify an already locally signed certificate with multiple UIDs: Restricted Project.
l10n daemon script <scripty@kde.org> committed rMTP6fbf3a1d4ffa: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed rKLEOPATRA4ef7d3eb7429: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 22 2025
May 22 2025
CarlSchwan committed rOJ3397b8ab0ada: reencrypt: First copy them email and then edit the copy (authored by CarlSchwan).
reencrypt: First copy them email and then edit the copy
Ifdef gpgme feature
CarlSchwan committed rOJdc40acb9dc10: client: use std::make_shared when possible (authored by CarlSchwan).
client: use std::make_shared when possible
• ebo removed a project from T7448: Draft: Kleopatra: Unify the information given on certificate import: gpd5x.
In light of the ticket T7630 this one is obsolete
• ebo renamed T7503: Kleopatra: change to secret key import window from Kleopatra: change secret key import behavior when importing more than one to Kleopatra: change to secret key import window.
• ebo renamed T7503: Kleopatra: change to secret key import window from Draft: Kleopatra: change secret key import behavior when importing more than one to Kleopatra: change secret key import behavior when importing more than one.
We decided to
- remove the "Cancel" Button in case only one secret key is imported (as this does the same as "No")
- in case of importing more than one secret key we want to change the text from "Cancel" to "No for all".
When you've implemented the link solution here, do the same for T5006