Required CVE Record Information
Description
Sylpheed 2.2.7 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Sylpheed from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
References 9 Total
- lists.gnupg.org: [gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME mailing-list
- securityreason.com: 2353 third-party-advisory
- securityfocus.com: 20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability mailing-list
- securityfocus.com: 22777 vdb-entry
- http://www.coresecurity.com/?action=item&id=1687
- securityfocus.com: 20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability mailing-list
- secunia.com: 24414 third-party-advisory
- securitytracker.com: 1017727 vdb-entry
- vupen.com: ADV-2007-0835 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 9 Total
- lists.gnupg.org: [gnupg-users] 20070306 [Announce] Multiple Messages Problem in GnuPG and GPGME mailing-listx_transferred
- securityreason.com: 2353 third-party-advisoryx_transferred
- securityfocus.com: 20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability mailing-listx_transferred
- securityfocus.com: 22777 vdb-entryx_transferred
- http://www.coresecurity.com/?action=item&id=1687 x_transferred
- securityfocus.com: 20070305 CORE-2007-0115: GnuPG and GnuPG clients unsigned data injection vulnerability mailing-listx_transferred
- secunia.com: 24414 third-party-advisoryx_transferred
- securitytracker.com: 1017727 vdb-entryx_transferred
- vupen.com: ADV-2007-0835 vdb-entryx_transferred