Mandriva Linux Security Advisory – GnuPG prior to 1.4.7 and GPGME prior to 1.1.4, when run from the command line, did not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components. This could allow a remote attacker to forge the contents of an email message without detection.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/55023/MDKSA-2007-059.txt
Source: https://packetstormsecurity.com/files/55023/Mandriva-Linux-Security-Advisory-2007.059.html

