Required CVE Record Information
Description
KMail 1.9.5 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
References 9 Total
- lists.gnupg.org: [gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME mailing-list
- securityreason.com: 2353 third-party-advisory
- securityfocus.com: 20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability mailing-list
- http://www.coresecurity.com/?action=item&id=1687
- securityfocus.com: 20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability mailing-list
- secunia.com: 24413 third-party-advisory
- securityfocus.com: 22759 vdb-entry
- securitytracker.com: 1017727 vdb-entry
- vupen.com: ADV-2007-0835 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 9 Total
- lists.gnupg.org: [gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME mailing-listx_transferred
- securityreason.com: 2353 third-party-advisoryx_transferred
- securityfocus.com: 20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability mailing-listx_transferred
- http://www.coresecurity.com/?action=item&id=1687 x_transferred
- securityfocus.com: 20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability mailing-listx_transferred
- secunia.com: 24413 third-party-advisoryx_transferred
- securityfocus.com: 22759 vdb-entryx_transferred
- securitytracker.com: 1017727 vdb-entryx_transferred
- vupen.com: ADV-2007-0835 vdb-entryx_transferred