Commit graph

4 commits

Author SHA1 Message Date
Thomas Klausner
03b18d0c42 Add another vulnerability. 2008-03-25 23:00:49 +00:00
Adrian Portelli
87a0d96aec Add security note 2005-11-21 22:55:44 +00:00
pancake ;)
9298ceffe0 Update to the latest 2.9.7
- remove TODO (so this commit fixes it)
- 2.9.6 is broken (as gnump3d's Changelog says)
- this version fixes two important security problems (update highly recommended)
  + XSS bug
  + CrossPath
- fix homepage (from savannah to gnu)
- fix PLIST (clean remove of share/gnump3d directory)
- check tarball GPG signature (it's OK)

$ gpg --import http://www.gnu.org/software/gnump3d/gnump3d@steve.org.uk.gpg
$ gpg --verify gnump3d-2.9.7.tar.bz2.sig /usr/pkgsrc/distfiles/gnump3d-2.9.7.tar.bz2
gpg: Signature made Fri Oct 28 16:13:36 2005 CEST using DSA key ID CD4C0D9D
gpg: Good signature from "Steve Kemp <steve@steve.org.uk>"
gpg:                 aka "Steve Kemp <skx@tardis.ed.ac.uk>"
gpg:                 aka "Steve Kemp <skx@debian.org>"
gpg:                 aka "Steve Kemp <gnump3d@steve.org.uk>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: DB1F F3FB 1D08 FC01 ED22  2243 C0CF C6B3 CD4C 0D9D
2005-10-28 17:34:03 +00:00
Thomas Klausner
fa9b2d3984 Newer version out. Security problem reported? 2005-10-28 15:23:37 +00:00