CVE-2007-1263
Summary
| CVE | CVE-2007-1263 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-03-06 20:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Mandriva update for gnupg and gpgme - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| issues.rpath.com/browse/RPL-1111 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| Object not found! | af854a3a-2127-422b-91ae-364da2661108 | lists.suse.com | |
| Trustix update for php4 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| GnuPG Signed Message Arbitrary Content Injection Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| GnuPG and Several E-mail Clients Let Remote Users Inject Unsigned Data into Signed Messages - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| ASA-2007-144 (RHSA-2007-0106) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Ubuntu update for gnupg, gnupg2 and libgpgme - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| GnuPG and GnuPG clients unsigned data injection vulnerability - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Debian update for gnupg - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-432-1: GnuPG vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | fedoranews.org | |
| Debian -- Security Information -- DSA-1266-1 gnupg | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| patches.sgi.com/support/free/security/advisories/20070301-01-P.asc | af854a3a-2127-422b-91ae-364da2661108 | patches.sgi.com | |
| Core Security | CoreLabs | af854a3a-2127-422b-91ae-364da2661108 | www.coresecurity.com | Patch, Vendor Advisory |
| Slackware update for gnupg - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora Core 5 Update: gnupg-1.4.7-1 | FedoraNEWS.ORG | af854a3a-2127-422b-91ae-364da2661108 | fedoranews.org | |
| USN-432-2: GnuPG2, GPGME vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| [Announce] Multiple Messages Problem in GnuPG and GPGME | af854a3a-2127-422b-91ae-364da2661108 | lists.gnupg.org | |
| Fedora update for gnupg - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| rPath update for gnupg - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Avaya Products Incorrect GnuPG Usage - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SUSE update for gpg - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat update for gnupg - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| www.trustix.org/errata/2007/0009 | af854a3a-2127-422b-91ae-364da2661108 | www.trustix.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.