PT-2007-1068 · Gnu+1 · Gnupg+1

Gerardo Richarte

·

Publicado

2007-03-06

·

Atualizado

2018-10-16

·

CVE-2007-1263

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: GnuPG versions 1.0.7 through 1.2.6 GnuPG versions 1.4.6 and earlier
Description: The issue may lead to a breach of confidentiality, integrity, and availability of protected information. It can be exploited remotely. The problem is related to the visual distinction of signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.
Recommendations: For GnuPG versions 1.0.7 through 1.2.6, update to a version later than 1.2.6 to resolve the issue. For GnuPG versions 1.4.6 and earlier, update to a version later than 1.4.6 to resolve the issue. As a temporary workaround, consider visually verifying the authenticity of OpenPGP messages to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-07238
BDU:2015-07239
BDU:2015-07240
CVE-2007-1263
DSA-1266-1
RHSA-2007:0106
RHSA-2007:0107
RHSA-2007_0106
RHSA-2007_0107

Produtos afetados

Gnupg
Red Hat