Back to search
CVE-2007-1263
Published: Mar 6, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://issues.rpath.com/browse/RPL-1111
x_refsource_CONFIRM
2007-0009
vendor-advisory
x_refsource_TRUSTIX
http://support.avaya.com/elmodocs2/security/ASA-2007-144.htm
x_refsource_CONFIRM
FEDORA-2007-315
vendor-advisory
x_refsource_FEDORA
24407
third-party-advisory
x_refsource_SECUNIA
[gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME
mailing-list
x_refsource_MLIST
24438
third-party-advisory
x_refsource_SECUNIA
FEDORA-2007-316
vendor-advisory
x_refsource_FEDORA
24650
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:10496
vdb-entry
signature
x_refsource_OVAL
2353
third-party-advisory
x_refsource_SREASON
RHSA-2007:0107
vendor-advisory
x_refsource_REDHAT
DSA-1266
vendor-advisory
x_refsource_DEBIAN
20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability
mailing-list
x_refsource_BUGTRAQ
24511
third-party-advisory
x_refsource_SECUNIA
USN-432-1
vendor-advisory
x_refsource_UBUNTU
http://www.coresecurity.com/?action=item&id=1687
x_refsource_MISC
20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability
mailing-list
x_refsource_BUGTRAQ
24734
third-party-advisory
x_refsource_SECUNIA
24419
third-party-advisory
x_refsource_SECUNIA
24544
third-party-advisory
x_refsource_SECUNIA
USN-432-2
vendor-advisory
x_refsource_UBUNTU
24420
third-party-advisory
x_refsource_SECUNIA
24875
third-party-advisory
x_refsource_SECUNIA
24365
third-party-advisory
x_refsource_SECUNIA
MDKSA-2007:059
vendor-advisory
x_refsource_MANDRIVA
RHSA-2007:0106
vendor-advisory
x_refsource_REDHAT
22757
vdb-entry
x_refsource_BID
1017727
vdb-entry
x_refsource_SECTRACK
SUSE-SA:2007:024
vendor-advisory
x_refsource_SUSE
ADV-2007-0835
vdb-entry
x_refsource_VUPEN
24489
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now