CVE-2007-1266
published 2007-03-06CVE-2007-1266: Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNIPAN
EXPLOIT
EPSS
5.05%
91.3th percentile
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | evolution | — | — |
| gnome | evolution | <= 2.8.1 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hr5c-fh4q-4782: Evolution 2
ghsa_unreviewed·2022-05-01
CVE-2007-1266 [MEDIUM] GHSA-hr5c-fh4q-4782: Evolution 2
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
OSV
CVE-2007-1266: Evolution 2
osv·2007-03-06·CVSS 5.0
CVE-2007-1266 [MEDIUM] CVE-2007-1266: Evolution 2
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
Debian
CVE-2007-1266: evolution - Evolution 2.8.1 and earlier does not properly use the --status-fd argument when ...
vendor_debian·2007·CVSS 5.0
CVE-2007-1266 [MEDIUM] CVE-2007-1266: evolution - Evolution 2.8.1 and earlier does not properly use the --status-fd argument when ...
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No writeups or analysis indexed.
http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.htmlhttp://secunia.com/advisories/24412http://securityreason.com/securityalert/2353http://www.coresecurity.com/?action=item&id=1687http://www.securityfocus.com/archive/1/461958/100/0/threadedhttp://www.securityfocus.com/archive/1/461958/30/7710/threadedhttp://www.securityfocus.com/bid/22760http://www.securitytracker.com/id?1017727http://www.vupen.com/english/advisories/2007/0835http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.htmlhttp://secunia.com/advisories/24412http://securityreason.com/securityalert/2353http://www.coresecurity.com/?action=item&id=1687http://www.securityfocus.com/archive/1/461958/100/0/threadedhttp://www.securityfocus.com/archive/1/461958/30/7710/threadedhttp://www.securityfocus.com/bid/22760http://www.securitytracker.com/id?1017727http://www.vupen.com/english/advisories/2007/0835
2007-03-06
Published