[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [SECURITY] [DSA 978-1] New GnuPG packages fix invalid success return



On Fri, Feb 17, 2006 at 09:30:50AM +0100, Martin Schulze wrote:
> For the stable distribution (sarge) this problem has been fixed in
> version 1.4.1-1sarge1.

<SNIP>
 
>   AMD64 architecture:
> 
>     http://security.debian.org/pool/updates/main/g/gnupg/gnupg_1.4.1-1sarge1_amd64.deb
>       Size/MD5 checksum:  1962898 4ecee788f9743005d120cbb7bcfce928

This won't upgrade automatically as the version in Sarge/AMD64 is
higher, specifically "1.4.1-1.0.1". According to pdo.d.n, all other
archs have "1.4.1-1".

By my reading of Debian Policy[1], the comparison of "1.0.1" and
"1sarge1" compares the 1s numerically (equal) and then compares the '.'
to the 's', which results in the '.' having a lower version.

I don't know enough about security version numbering practice to suggest
a fix.

Brian

[1] http://www.debian.org/doc/debian-policy/ch-controlfields.html#s-f-Version

-- 
Website: http://www.netsoc.tcd.ie/~bbrazil

Attachment: signature.asc
Description: Digital signature


Reply to: