Common Vulnerabilities and Exposures assigned an identifier CVE-2007-1263 to the following vulnerability: GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection. References: http://www.securityfocus.com/archive/1/archive/1/461958/100/0/threaded http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html http://www.coresecurity.com/?action=item&id=1687 https://issues.rpath.com/browse/RPL-1111 http://support.avaya.com/elmodocs2/security/ASA-2007-144.htm http://www.debian.org/security/2007/dsa-1266 http://fedoranews.org/cms/node/2776 http://fedoranews.org/cms/node/2775 http://www.mandriva.com/security/advisories?name=MDKSA-2007:059 http://www.redhat.com/support/errata/RHSA-2007-0106.html http://www.redhat.com/support/errata/RHSA-2007-0107.html ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc http://lists.suse.com/archive/suse-security-announce/2007-Mar/0008.html http://www.trustix.org/errata/2007/0009/ http://www.ubuntu.com/usn/usn-432-1 http://www.ubuntu.com/usn/usn-432-2 http://www.securityfocus.com/bid/22757 http://www.frsirt.com/english/advisories/2007/0835 http://www.securitytracker.com/id?1017727 http://secunia.com/advisories/24365 http://secunia.com/advisories/24420 http://secunia.com/advisories/24438 http://secunia.com/advisories/24489 http://secunia.com/advisories/24511 http://secunia.com/advisories/24544 http://secunia.com/advisories/24734 http://secunia.com/advisories/24650 http://secunia.com/advisories/24875 http://secunia.com/advisories/24407 http://secunia.com/advisories/24419 http://securityreason.com/securityalert/2353
This was addressed via: Red Hat Enterprise Linux version 2.1 (RHSA-2007:0106) Red Hat Enterprise Linux version 3 (RHSA-2007:0106) Red Hat Enterprise Linux version 4 (RHSA-2007:0106) Red Hat Enterprise Linux version 5 (RHSA-2007:0107)