According to an RKHunter test I have a vulnerability:

* Application version scan
- Exim MTA 4.43 [ OK ]
- GnuPG 1.2.1 [ Vulnerable ]
- Apache [unknown] [ OK ]
- Bind DNS [unknown] [ OK ]
- OpenSSL 0.9.7e [ Unknown ]
- PHP 4.3.9 [ OK ]
- PHP 4.3.9 [ OK ]
- Procmail MTA 3.22 [ OK ]
- ProFTPd 1.2.10 [ OK ]
- OpenSSH 3.9p1 [ OK ]
- OpenSSH [unknown] [ OK ]

I originally had problems with OpenSSL and OpenSSH but followed the directions at http://eth0.us/?q=node/4 and updated those successfully.

Now two questions:

How do I update GnuPG?
Should I be concerned with the "Unknown" status for OpenSSL?