Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

Pascal is a language for children wanting to be naughty. -- Dr. Kasi Ananthanarayanan


computers / alt.privacy.anon-server / Security Update - Gpg4win 4.0.4 released

SubjectAuthor
* Security Update - Gpg4win 4.0.4 releasedYamn Remailer
`* Re: Security Update - Gpg4win 4.0.4 releasedbtdt
 `* Re: Security Update - Gpg4win 4.0.4 releasedHal
  +* Re: Security Update - Gpg4win 4.0.4 releasedYamn Remailer
  |`- Re: Security Update - Gpg4win 4.0.4 releasedHal
  `- Re: Security Update - Gpg4win 4.0.4 releasedFritz Wuehler

1
Security Update - Gpg4win 4.0.4 released

<20221018.154238.4d2428c4@mixmin.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=12930&group=alt.privacy.anon-server#12930

  copy link   Newsgroups: alt.privacy.anon-server
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset=us-ascii
Message-Id: <20221018.154238.4d2428c4@mixmin.net>
From: nore...@mixmin.net (Yamn Remailer)
Date: Tue, 18 Oct 2022 15:42:38 +0100
Subject: Security Update - Gpg4win 4.0.4 released
Mime-Version: 1.0
Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!alphared!sewer!news.dizum.net!not-for-mail
Organization: dizum.com - The Internet Problem Provider
X-Abuse: abuse@dizum.com
Injection-Info: sewer.dizum.com - 2001::1/128
 by: Yamn Remailer - Tue, 18 Oct 2022 14:42 UTC

Hello,

Gpg4win version 4.0.4 is released!

<https://www.gpg4win.org/download.html>

A severe bug has been found in libksba, the library used
by GnuPG for parsing the ASN.1 structures as used by S/MIME.
The bug ( https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html
CVE-2022-3515) affects all versions of libksba before 1.6.2
and may be used for remote code execution.

*Updating to this new version is thus important*.

It is important to us that Gpg4win continues to be available
as Free Software which can be downloaded anonymously without
costs. Because we know that this is the only way for some
people to get a software product which enables them to protect
their communication. As Gpg4win maintenance needs to be funded
nevertheless, we recommend that you set the price for yourself
that shows the value of Gpg4win.

For use with official documents with VS-NfD / EU / NATO RESTRICTED
classification gnupg.com offers the option to obtain the approved
GnuPG VS-Desktop version.

Details about Gpg4win 4.0.4:

<https://files.gpg4win.org/README-4.0.4.en.txt>

Highlights in Gpg4win Version 4.0.4 (2022-10-17)
-------------------------------------------
* GnuPG: Security update to 2.3.8 to fix CVE-2022-3515.
* Kleopatra: Multiple improvements related to accessibility and user
experience.
* GpgOL: An issue has been fixed which could cause delays when viewing
unencrypted mails.

Re: Security Update - Gpg4win 4.0.4 released

<tipk84$om5$1@gioia.aioe.org>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=12931&group=alt.privacy.anon-server#12931

  copy link   Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!aioe.org!1k0FC4bbgUznAzJMPSwfsA.user.46.165.242.75.POSTED!not-for-mail
From: btd...@fall.invalid (btdt)
Newsgroups: alt.privacy.anon-server
Subject: Re: Security Update - Gpg4win 4.0.4 released
Date: Wed, 19 Oct 2022 14:42:33 -0500
Organization: Aioe.org NNTP Server
Message-ID: <tipk84$om5$1@gioia.aioe.org>
References: <20221018.154238.4d2428c4@mixmin.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="25285"; posting-host="1k0FC4bbgUznAzJMPSwfsA.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.3.3
Content-Language: en-US
X-Notice: Filtered by postfilter v. 0.9.2
 by: btdt - Wed, 19 Oct 2022 19:42 UTC

On 10/18/2022 9:42 AM, Yamn Remailer wrote:
> Hello,
>
> Gpg4win version 4.0.4 is released!
>
> <https://www.gpg4win.org/download.html>
>
> A severe bug has been found in libksba, the library used
> by GnuPG for parsing the ASN.1 structures as used by S/MIME.
> The bug ( https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html
> CVE-2022-3515) affects all versions of libksba before 1.6.2
> and may be used for remote code execution.
>
> *Updating to this new version is thus important*.
>
>
> It is important to us that Gpg4win continues to be available
> as Free Software which can be downloaded anonymously without
> costs. Because we know that this is the only way for some
> people to get a software product which enables them to protect
> their communication. As Gpg4win maintenance needs to be funded
> nevertheless, we recommend that you set the price for yourself
> that shows the value of Gpg4win.
>
> For use with official documents with VS-NfD / EU / NATO RESTRICTED
> classification gnupg.com offers the option to obtain the approved
> GnuPG VS-Desktop version.
>
> Details about Gpg4win 4.0.4:
>
> <https://files.gpg4win.org/README-4.0.4.en.txt>
>
>
> Highlights in Gpg4win Version 4.0.4 (2022-10-17)
> -------------------------------------------
> * GnuPG: Security update to 2.3.8 to fix CVE-2022-3515.
> * Kleopatra: Multiple improvements related to accessibility and user
> experience.
> * GpgOL: An issue has been fixed which could cause delays when viewing
> unencrypted mails.
>

I've been away for a while due to health issues. Just came back looking
to see if there is a new version of GPG4win. Got a new pc, now, too,
and don't have the old GPG version on this pc, yet. Everything I do
have is set up for being portable on a thumb drive. I'm guessing my
keys are old, too. I downloaded the new version you posted, here, and
have been reading documentation. Haven't installed it yet. I think my
brain is going to explode because it's been a couple years since I've
messed with my old GPG!

Re: Security Update - Gpg4win 4.0.4 released

<0ho0lhhtnna76aujlg34amuv223tll5d17@4ax.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=12934&group=alt.privacy.anon-server#12934

  copy link   Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!news.nntp4.net!aioe.org!so5MS0Eyiodm1SANO+4kww.user.46.165.242.75.POSTED!not-for-mail
From: Hal...@invalid.com
Newsgroups: alt.privacy.anon-server
Subject: Re: Security Update - Gpg4win 4.0.4 released
Date: Wed, 19 Oct 2022 15:49:23 -0500
Organization: Aioe.org NNTP Server
Message-ID: <0ho0lhhtnna76aujlg34amuv223tll5d17@4ax.com>
References: <20221018.154238.4d2428c4@mixmin.net> <tipk84$om5$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: gioia.aioe.org; logging-data="8673"; posting-host="so5MS0Eyiodm1SANO+4kww.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Newsreader: Forte Agent 1.93/32.576 English (American)
X-No-Archive: yes
X-Notice: Filtered by postfilter v. 0.9.2
 by: Hal...@invalid.com - Wed, 19 Oct 2022 20:49 UTC

On Wed, 19 Oct 2022 14:42:33 -0500, btdt <btdt@fall.invalid> wrote:

>On 10/18/2022 9:42 AM, Yamn Remailer wrote:
>> Hello,
>>
>> Gpg4win version 4.0.4 is released!
>>
>> <https://www.gpg4win.org/download.html>
>>
>> A severe bug has been found in libksba, the library used
>> by GnuPG for parsing the ASN.1 structures as used by S/MIME.
>> The bug ( https://www.gnupg.org/blog/20221017-pepe-left-the-ksba.html
>> CVE-2022-3515) affects all versions of libksba before 1.6.2
>> and may be used for remote code execution.
>>
>> *Updating to this new version is thus important*.
>>
>>
>> It is important to us that Gpg4win continues to be available
>> as Free Software which can be downloaded anonymously without
>> costs.

That's a lie.

It cannot be downloaded unless you make a "donation" - I think the
minimum cost was $15.

I don't give a damn if it takes $$, time and effort to keep it going.
That's no reason for claiming it's free - it ain't.

Re: Security Update - Gpg4win 4.0.4 released

<20221020.001847.2e68e8cf@mixmin.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=12937&group=alt.privacy.anon-server#12937

  copy link   Newsgroups: alt.privacy.anon-server
Subject: Re: Security Update - Gpg4win 4.0.4 released
Newsgroups: alt.privacy.anon-server
From: nore...@mixmin.net (Yamn Remailer)
MIME-Version: 1.0
References: <0ho0lhhtnna76aujlg34amuv223tll5d17@4ax.com>
Injection-Info: neodome.net;
posting-account="mail2news";
key="ex3W3WxBjBEzDdrRQhPw9z0o7cZ3cfZXXj5XR0PoCUBhDSMZWt0UCrwQasNpWmhFD6ctlb
Fxt1PR0Jx9BWSakd57j3U1VBNuFd1qy3F7qO073JRiCSr3JbXtCm1N6gJ7I2Gv6LzWR5vKBtWpM
ChkYabh9YF28zfq8IB4NSDl5ut9rmOD2tbPMQcp/Das/2vUz+2bxkecSpdT7S/8+PK3nNcV9l2Z
hTRZ+4uCXVIzWhXTAF3yux4jtOQW22sDdf9Dolpwlp5s50V0b24HYbeYn+TtpYfr5GMfswD7Jeu
yT9OjnRLA/xFikhLbmW7bID4iNAqltvdQSNwkTaZPcQQ2ew==";
data="U2FsdGVkX1/DDjwtNbZGmLsACGImyMbWkHOTdXzIdujRH3YVJcyGNowJfxijNtijjbgih
Nt1fBfpB0ZnDw/BB/3qPiTB9duOMqD+k1pRgKP0Uab3P0OiuVqJ34XhKasqi/mr6eKPcc9zIrHw
ZtI2uh0FfL3Q4BqXlZ8gG+rlj8gb4LNsxcgN42iX/cbreUG+jKjAsfP0+3eERrRJD5/kecebMy8
V48CD4Lg7XAv0pjGkOsNnNC4XqiNYIBZGw5xqNKhfIg4naM0VFh+tTXSIcUMR4hHW9GiU7AzZbe
Lk77YiDS+mkEuozvMspldeKiGRRphBKwQhC9hAKPFOcCPAez9kfhriHFjAshE7RCIYFHDR48i7D
eEauEWHzS/nbJsNVfco1CfiZ3Vkpl/cZTlqbqgztZ+vJFMqWP9qSH7uVbK/iagx4Bj8rHBH/VPb
/IvLmdcX4B3fOzsTJEEkABquqjh82QM+A0PYyDu4YvQvW1PmH8bPuukuE+POUaUU5EBKkdKIzQV
rmsNXkoP8SE6iLcpGsm7dJJVW6FGnorF1I2T3vHMarBD8yWIIsjLPrSwyWVC5/zMpEeM9yZW/1r
h58sL0tEVIGH0CT5CWvscbXuR9w4n3ZeuapIdGsXk4uutKsHWclW2x/NIWkcylhqdjRy0wXL5wx
bcUhUBSZWZOQD17liQSQRcqKTeBZyqAs5M4/Jb2SXSyK2Z17XQmoT1/mrkmRPOOcebX/HItpMdW
TEYou8TQLTTs2PtRuzRBRHuQRD4WqvcOnwGv5ctKxbGfoqdoKY05WbsniPStzLqcQsGayDEwgZE
tFaPFhdXpny+fi+6ryXqtTEAPmHArq/4tYVzjQqYEqwBlpV0K8bvEY2UjpiSyT7GhlBY0gT6CnE
rK41xkwPRZDirFODIIMxECEU3CDQ9SlLvoDPuHCNYIF7znD/hlNkcd6QZ5BelilIQpDLY5403k3
FVgRVas8Ujfb6h+UqS8Apm9eTFAxhaqzWgNwMB1Y3GU7+QwPrJRx3ZEwVHSHjeD0Tys/VOPLaAw
ElQZaXWIVk/S7nZly7RvN3Eky4Ix3YJmG/ZeVwpjr09umIzRuPJR8Q3Kg2ItnT3ZiDn9vhZ5jcU
JGlRvafLgrt7ZEl7v2wHBJTFYewvD5hXy8aM64xLrZT46X/OwIz2mrWSuxUH/tYQEkWfHPmq05d
cc7fEduRIt+RqrwHCdz84GgpfNmY2DxQ+YCCLEgSxcX35pB3UxiRzv5/bUL35M5x+VKUQB8E21G
BUmFNzJEGTv7zbmphIixssYSTl+pt0kw5qFjz4Y1cskOQQi/quTcrfXJQ7hGwHuPIXISTHWnig+
6C/kokO7DSr5XKaLiVo9qvcPBWBi4AKyW8AdKFLqbT5WJIdDjKp4GG3yT0WRzrAhLp6KuuPiaFf
Rt8HoCgQj1YViuoMBgCbLWHCrK9anhyqOpZ9q9bjCo3r8ulCPvaQs4yTU4pwQue8CnfgYuwvNMQ
wdce0Ehvv8vjFDC7ob2GXsvg0sN6Uhn8SBfOttvM1lBlA34TK1QO3LLW4DvoWWNLkcefyUbYlw2
Af+y2Wdd48Xhw/dRxNC5k3ZJYAKNZSVMKWA6KrpYmupfQ7+HcT7DYCiWZdtZWVe3uhzxGs63pIA
JhWdNA/Ph9Ld2N12/ig7DpK4NmFqTN1AtwnLCKXQT/73A3O+hJ1f6HboknH5W/XSpxYfEXsD6D+
PMhrgUL7HEncMg34psGr/FXSfSui7OaWU0voI54w8euC4QpeKKBw4b27jKMhjTXQZzeGNIysnte
I6f31wWNBbfn1SnwHGwghvDE0woa591fTA4RyHAuFTrTLJLpMGyaL5oj7uv5pMnE3pe86Tpcyl0
1FjGYPGjW4vYDJ+RUwCJgdUmOZ1IalDwX/YK5Yh4DUbzJyQme9S";
mail-complaints-to="abuse@neodome.net"
Date: Thu, 20 Oct 2022 00:18:47 +0100
Path: i2pn2.org!i2pn.org!news.neodome.net!mail2news
Injection-Date: Wed, 19 Oct 2022 23:20:01 +0000 (UTC)
Comments: This message was transferred to Usenet via mail2news gateway at
<mail2news@neodome.net>. Please send questions and concerns to
<admin@neodome.net>. Report inappropriate use to <abuse@neodome.net>.
Content-Type: text/plain; charset=us-ascii
Message-ID: <20221020.001847.2e68e8cf@mixmin.net>
Content-Transfer-Encoding: 7bit
 by: Yamn Remailer - Wed, 19 Oct 2022 23:18 UTC

>That's a lie.

No its not !
Look again, there is another choice, "To Donate Zero dollars."

If I was more financial, I would donate.

Look closer Hal before you hit the keyboard.

Re: Security Update - Gpg4win 4.0.4 released

<0u31lh9ftn9vb7rerd1nsuo0q2korpnirg@4ax.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=12939&group=alt.privacy.anon-server#12939

  copy link   Newsgroups: alt.privacy.anon-server
From: Hal...@invalid.com
Newsgroups: alt.privacy.anon-server
Subject: Re: Security Update - Gpg4win 4.0.4 released
Date: Wed, 19 Oct 2022 19:03:40 -0500
Message-Id: <0u31lh9ftn9vb7rerd1nsuo0q2korpnirg@4ax.com>
References: <0ho0lhhtnna76aujlg34amuv223tll5d17@4ax.com> <20221020.001847.2e68e8cf@mixmin.net>
X-Newsreader: Forte Agent 1.93/32.576 English (American)
X-No-Archive: yes
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Lines: 17
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!peer01.iad!feed-me.highwinds-media.com!news.highwinds-media.com!feeder.usenetexpress.com!tr1.iad1.usenetexpress.com!news.newsgroupdirect.com!not-for-mail
Nntp-Posting-Date: Thu, 20 Oct 2022 00:03:41 +0000
Organization: NewsgroupDirect
X-Complaints-To: abuse@newsgroupdirect.com
X-Received-Bytes: 1238
 by: Hal...@invalid.com - Thu, 20 Oct 2022 00:03 UTC

On Thu, 20 Oct 2022 00:18:47 +0100, Yamn Remailer <noreply@mixmin.net>
wrote:

>>That's a lie.
>
>No its not !
>Look again, there is another choice, "To Donate Zero dollars."
>
>If I was more financial, I would donate.
>
>Look closer Hal before you hit the keyboard.

I'll be darned. You're right. I didn't even notice it. I guess I was
blinded by all the $ signs.

Oh, well, it's only Wednesday. I still got 3-4 days left in the week
to get something right for once. :o(

Re: Security Update - Gpg4win 4.0.4 released

<851090eff1d3899f461ef4ac52890490@msgid.frell.theremailer.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=12942&group=alt.privacy.anon-server#12942

  copy link   Newsgroups: alt.privacy.anon-server
From: fri...@spamexpire-202210.rodent.frell.theremailer.net (Fritz Wuehler)
References: <0ho0lhhtnna76aujlg34amuv223tll5d17@4ax.com>
Subject: Re: Security Update - Gpg4win 4.0.4 released
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <851090eff1d3899f461ef4ac52890490@msgid.frell.theremailer.net>
Date: Thu, 20 Oct 2022 12:01:46 +0200
Newsgroups: alt.privacy.anon-server
Path: i2pn2.org!i2pn.org!aioe.org!news.uzoreto.com!alphared!sewer!news.dizum.net!not-for-mail
Organization: dizum.com - The Internet Problem Provider
X-Abuse: abuse@dizum.com
Injection-Info: sewer.dizum.com - 2001::1/128
 by: Fritz Wuehler - Thu, 20 Oct 2022 10:01 UTC

On 10/19/2022 1:49 PM, Hal@invalid.com wrote:

> That's a lie.
>
> It cannot be downloaded unless you make a "donation" - I think the
> minimum cost was $15.
>
> I don't give a damn if it takes $$, time and effort to keep it going.

> That's no reason for claiming it's free - it ain't.

Learn to read before you post.

I just downloaded and selected $0.

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor