CVE-2007-1266

Publication date 6 March 2007

Last updated 24 July 2024


Ubuntu priority

Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

Read the notes from the security team

Status

Package Ubuntu Release Status
evolution 7.04 feisty Ignored
6.10 edgy Ignored
6.06 LTS dapper Ignored

Notes


kees

feature-request not security issue since gpg is fixed with CVE-2007-1263