PGPsdk based products contain a flaw related to the authentication of PGP key user IDs. The issue is due to the software not properly authenticating and warning a user when a trusted third party key is used to forge signatures with an invalid key. The attacker could then add an unsigned second user ID to this key, which could be switched to primary.
Classification
Location:
Remote/Network Access Required
Attack Type:
Authentication Management
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
Solution
Upgrade to version 7.0.4/7.2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.