CVE-2007-1264
EPSS 12.4%
Description
Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
How to fix CVE-2007-1264
To remediate CVE-2007-1264, upgrade the affected package to a fixed version below.
- Debian/enigmail—upgrade to 2:0.95.0+1-1 or later
Is CVE-2007-1264 being exploited?
Moderate — EPSS is 12.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2:0.95.0+1-1