CVE-2007-1266
CVE-2007-1266
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/29691unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.htmlhttp://secunia.com/advisories/24412http://securityreason.com/securityalert/2353http://www.coresecurity.com/?action=item&id=1687http://www.securityfocus.com/archive/1/461958/100/0/threadedhttp://www.securityfocus.com/archive/1/461958/30/7710/threadedhttp://www.securityfocus.com/bid/22760http://www.securitytracker.com/id?1017727http://www.vupen.com/english/advisories/2007/0835