CVE-2007-1264

Publication date 6 March 2007

Last updated 24 July 2024


Ubuntu priority

Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

Read the notes from the security team

Status

Package Ubuntu Release Status
enigmail 7.04 feisty Ignored
6.10 edgy Ignored
6.06 LTS dapper Ignored

Notes


kees

feature-request not security issue since gpg is fixed with CVE-2007-1263