CVE-2007-1265: High severity KDE K-Mail vulnerability
KMail 1.9.5 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1265?
CVE-2007-1265 is classified as a medium severity vulnerability.
How do I fix CVE-2007-1265?
To fix CVE-2007-1265, upgrade KMail to a version that addresses this vulnerability, such as KMail 1.9.6 or later.
What types of attacks can exploit CVE-2007-1265?
CVE-2007-1265 can be exploited by remote attackers to forge the contents of OpenPGP messages.
Which versions of KMail are affected by CVE-2007-1265?
CVE-2007-1265 affects KMail versions 1.9.5 and earlier.
What is the impact of CVE-2007-1265 on KMail users?
The impact of CVE-2007-1265 on KMail users is the inability to visually distinguish between signed and unsigned portions of messages, leading to potential misinformation.