CVE Vulnerabilities

CVE-2007-1265

Published: Mar 06, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:C/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

KMail 1.9.5 and earlier does not properly use the –status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

Affected Software

NameVendorStart VersionEnd Version
K-mailKde0.0.29.2 (including)0.0.29.2 (including)
K-mailKde1.0.23 (including)1.0.23 (including)
K-mailKde1.0.24 (including)1.0.24 (including)
K-mailKde1.0.25 (including)1.0.25 (including)
K-mailKde1.0.26 (including)1.0.26 (including)
K-mailKde1.0.27 (including)1.0.27 (including)
K-mailKde1.0.28 (including)1.0.28 (including)
K-mailKde1.0.29 (including)1.0.29 (including)
K-mailKde1.0.29.1 (including)1.0.29.1 (including)
K-mailKde1.0.29.2 (including)1.0.29.2 (including)
K-mailKde1.1 (including)1.1 (including)
K-mailKde1.2 (including)1.2 (including)
K-mailKde1.3.1 (including)1.3.1 (including)
K-mailKde1.7.1 (including)1.7.1 (including)
K-mailKde1.9.1 (including)1.9.1 (including)
K-mailKde1.86.2.36 (including)1.86.2.36 (including)
K-mailKde1.87 (including)1.87 (including)
K-mailKde1.88 (including)1.88 (including)
K-mailKde1.89 (including)1.89 (including)
K-mailKde1.90 (including)1.90 (including)
K-mailKde1.92 (including)1.92 (including)
K-mailKde1.93 (including)1.93 (including)
K-mailKde1.94 (including)1.94 (including)
K-mailKde1.95 (including)1.95 (including)
K-mailKde1.101 (including)1.101 (including)
K-mailKde1.102 (including)1.102 (including)

References