Lucene search

K
cve[email protected]CVE-2007-1265
HistoryMar 06, 2007 - 8:19 p.m.

CVE-2007-1265

2007-03-0620:19:00
web.nvd.nist.gov
31
kmail
gnupg
openpgp
cve-2007-1265
forged messages

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:C/A:N

6.4 Medium

AI Score

Confidence

Low

0.036 Low

EPSS

Percentile

91.7%

KMail 1.9.5 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

Affected configurations

NVD
Node
kdek-mailMatch0.0.29.2
OR
kdek-mailMatch1.0.23
OR
kdek-mailMatch1.0.24
OR
kdek-mailMatch1.0.25
OR
kdek-mailMatch1.0.26
OR
kdek-mailMatch1.0.27
OR
kdek-mailMatch1.0.28
OR
kdek-mailMatch1.0.29
OR
kdek-mailMatch1.0.29.1
OR
kdek-mailMatch1.0.29.2
OR
kdek-mailMatch1.1
OR
kdek-mailMatch1.2
OR
kdek-mailMatch1.3.1
OR
kdek-mailMatch1.7.1
OR
kdek-mailMatch1.9.1
OR
kdek-mailMatch1.86.2.36
OR
kdek-mailMatch1.87
OR
kdek-mailMatch1.88
OR
kdek-mailMatch1.89
OR
kdek-mailMatch1.90
OR
kdek-mailMatch1.92
OR
kdek-mailMatch1.93
OR
kdek-mailMatch1.94
OR
kdek-mailMatch1.95
OR
kdek-mailMatch1.101
OR
kdek-mailMatch1.102

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:C/A:N

6.4 Medium

AI Score

Confidence

Low

0.036 Low

EPSS

Percentile

91.7%