SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-1263

GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a…

MEDIUM 5.0EPSS 5.36%

Does this matter?

Lower severity and a low EPSS score (5.36%). Track it; it rarely justifies an emergency change on its own.

Description

GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
5.36% probability · 92th percentile
CISA KEV
Not listed
Affected
gnu/gpgme · gnupg/gnupg
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.