CVE-2007-1268

Publication date 6 March 2007

Last updated 24 July 2024


Ubuntu priority

Mutt 1.5.13 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Mutt from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.

Read the notes from the security team

Status

Package Ubuntu Release Status
mutt 7.04 feisty Ignored
6.10 edgy Ignored
6.06 LTS dapper Ignored

Notes


kees

feature-request not security issue since gpg is fixed with CVE-2007-1263