CVE-2007-1263

Impact:
Important
Public Date:
2007-03-05
Bugzilla:
430489: CVE-2007-1263 gnupg/gpgme signed message spoofing

The MITRE CVE dictionary describes this issue as:

GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.

Find out more about CVE-2007-1263 from the MITRE CVE dictionary dictionary and NIST NVD.

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux 4 (gnupg) RHSA-2007:0106 2007-03-06
Red Hat Enterprise Linux 2.1 (gnupg) RHSA-2007:0106 2007-03-06
Red Hat Enterprise Linux 5 (gnupg) RHSA-2007:0107 2007-03-14
Red Hat Enterprise Linux 3 (gnupg) RHSA-2007:0106 2007-03-06

Acknowledgements

Red Hat would like to thank Core Security Technologies for reporting this issue.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.