CVE-2007-1264
EPSS 4.6%
Description
Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
How to fix CVE-2007-1264
To remediate CVE-2007-1264, upgrade the affected package to a fixed version below.
- Debian/enigmail—upgrade to 2:0.95.0+1-1 or later
Is CVE-2007-1264 being exploited?
Low — EPSS is 4.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2:0.95.0+1-1