Bug#1006010: bullseye-pu: package php-crypt-gpg/1.6.4-2+deb11u1

2022-03-15 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2022-02-18 at 22:47 +0100, Guilhem Moulin wrote: > CVE-2022-24953: Crypt_GPG <1.6.7 does not prevent additional options > in > GPG calls, which presents a risk for certain environments and GPG > versions. > Please go ahead; thanks. Regards, Adam

Bug#1006010: bullseye-pu: package php-crypt-gpg/1.6.4-2+deb11u1

2022-02-18 Thread Guilhem Moulin
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu [ Reason ] CVE-2022-24953: Crypt_GPG <1.6.7 does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG versions. The Security Team