HomeEnigmailCVE-2007-1264

CVE-2007-1264

UNKNOWN
5.0CVSS
Published: 2007-03-06
Updated: 2025-04-09
AI Analysis

Description

Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

CVSS Metrics

Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Access Vector
network
Access Cmplx
low
Auth
none
Confidentiality
none
Integrity
partial
Availability
none
Weaknesses
NVD-CWE-Other

Metadata

Primary Vendor
ENIGMAIL
Published
3/6/2007
Last Modified
4/9/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

enigmail : enigmail

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief