PT-2007-1068 · Gnu+1 · Gnupg+1

Gerardo Richarte

·

Published

2007-03-06

·

Updated

2018-10-16

·

CVE-2007-1263

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: GnuPG versions 1.0.7 through 1.2.6 GnuPG versions 1.4.6 and earlier
Description: The issue may lead to a breach of confidentiality, integrity, and availability of protected information. It can be exploited remotely. The problem is related to the visual distinction of signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.
Recommendations: For GnuPG versions 1.0.7 through 1.2.6, update to a version later than 1.2.6 to resolve the issue. For GnuPG versions 1.4.6 and earlier, update to a version later than 1.4.6 to resolve the issue. As a temporary workaround, consider visually verifying the authenticity of OpenPGP messages to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07238
BDU:2015-07239
BDU:2015-07240
CVE-2007-1263
DSA-1266-1
RHSA-2007:0106
RHSA-2007:0107
RHSA-2007_0106
RHSA-2007_0107

Affected Products

Gnupg
Red Hat