Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-1263

24
FAUCET Score

CVE-2007-1263 describes a vulnerability in GnuPG versions 1.4.6 and earlier, and GPGME prior to 1.1.4, where the command-line interface fails to visually differentiate signed and unsigned sections within multi-component OpenPGP messages. This flaw could enable remote attackers to inject arbitrary content into a message, making it appear legitimate without detection. The vulnerability carries a CVSS score of 5.0, indicating a medium severity. It is easily exploitable over the network with low attack complexity and requires no authentication, potentially leading to unauthorized modification of information. While there is no evidence of active exploitation, an exploit (EDB-29689) exists on ExploitDB. The CVE has received minimal community discussion and media coverage, suggesting a low level of public awareness or concern.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.1.3CPE matchmatch criteria
cpe:2.3:a:gnu:gpgme:*:*:*:*:*:*:*:*
<= 1.4.6CPE matchmatch criteria
cpe:2.3:a:gnupg:gnupg:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
5.36%
Probability of exploitation in next 30 days
EPSS Percentile
91.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-29689 · Mar 5, 2007
This CVE's current EPSS score of 0.0536 is in the 89th percentile among its peer group of 23,701 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: gnupg-0:1.0.7-21
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: gnupg-0:1.2.1-20
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: gnupg-0:1.2.6-9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: gnupg-0:1.4.5-13
View patch

Vendor Advisories (1)

redhatCVE-2007-1263Important

gnupg/gpgme signed message spoofing

Mar 5, 2007

References

patches.sgi.com / support/free/security/advisories/20070301-01-P.asc
fedoranews.org / cms/node/2775
fedoranews.org / cms/node/2776
lists.gnupg.org / pipermail/gnupg-users/2007-March/030514.html
lists.suse.com / archive/suse-security-announce/2007-Mar/0008.html
secunia.com / advisories/24365
secunia.com / advisories/24407
secunia.com / advisories/24419
secunia.com / advisories/24420
secunia.com / advisories/24438
secunia.com / advisories/24489
secunia.com / advisories/24511
secunia.com / advisories/24544
secunia.com / advisories/24650
secunia.com / advisories/24734
secunia.com / advisories/24875
securityreason.com / securityalert/2353
issues.rpath.com / browse/RPL-1111
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10496
support.avaya.com / elmodocs2/security/ASA-2007-144.htm
coresecurity.com
PatchVendor Advisory
debian.org / security/2007/dsa-1266
mandriva.com / security/advisories
redhat.com / support/errata/RHSA-2007-0106.html
redhat.com / support/errata/RHSA-2007-0107.html
securityfocus.com / archive/1/461958/100/0/threaded
securityfocus.com / archive/1/461958/30/7710/threaded
securityfocus.com / bid/22757
securitytracker.com / id
trustix.org / errata/2007/0009
ubuntu.com / usn/usn-432-1
ubuntu.com / usn/usn-432-2
vupen.com / english/advisories/2007/0835