Gnupg incorrect malformed message verification Tavis Ormandy discovered that it is still possible to trick gnupg into incorrectly verifying a signed message. The patch is here: ftp://ftp.gnupg.org/gcrypt/gnupg/gnupg-1.4.2.1-1.4.2.2.diff.bz2
From User-Agent: XML-RPC gnupg-1.4.2.2-1 has been pushed for FC4, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
Hmm, don't know why this didn't get closed.