← Back

CVE-2007-1265

nvd nist
Published: Mar 6, 2007Modified: Apr 23, 2026

JSON object

Loading...
7.8
Vector
AV:N/AC:L/Au:N/C:N/I:C/A:N
Exploitability: 10.0 / Impact: 6.9
Source: NVD

Description

KMail 1.9.5 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents KMail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

Affected (26)

Products: Kde: K Mail
1 product
K Mail
Configuration A
26 vulnerable
Vulnerable SoftwareAffected Versions
Kde
Version 0.0.29.2
Version 1.0.23
Version 1.0.24
Version 1.0.25
Version 1.0.26
Version 1.0.27
Version 1.0.28
Version 1.0.29.1
Version 1.0.29.2
Version 1.0.29
Version 1.101
Version 1.102
Version 1.1
Version 1.2
Version 1.3.1
Version 1.7.1
Version 1.86.2.36
Version 1.87
Version 1.88
Version 1.89
Version 1.9.1
Version 1.90
Version 1.92
Version 1.93
Version 1.94
Version 1.95

References (18)

Timeline

No history available yet.