CVE-2007-1263: Medium severity GNU GPGME vulnerability
GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1263?
CVE-2007-1263 is considered a moderate severity vulnerability due to the potential for message forgery.
How do I fix CVE-2007-1263?
To mitigate CVE-2007-1263, upgrade GnuPG to version 1.4.7 or later and GPGME to version 1.1.4 or later.
What systems are affected by CVE-2007-1263?
CVE-2007-1263 affects GnuPG versions 1.4.6 and earlier and GPGME versions prior to 1.1.4.
What type of attack does CVE-2007-1263 facilitate?
CVE-2007-1263 allows attackers to forge the contents of OpenPGP messages without detection.
How can I confirm if I am vulnerable to CVE-2007-1263?
You can confirm vulnerability to CVE-2007-1263 by checking if your GnuPG or GPGME versions are below the fixed versions.