D20757: Test mails for Decryption Oracle based on replying to PGP or S/MIME.
Sandro Knauß
noreply at phabricator.kde.org
Tue Apr 23 15:04:42 BST 2019
knauss added a comment.
In D20757#454735 <https://phabricator.kde.org/D20757#454735>, @vkrause wrote:
> This makes sense I think (and should go in IMHO), but I'm not sure if it is complete to cover all of bug 404698.
>
> - Do we need to be concerned about forwarding (which does include attachments AFAIK)?
make sense, yes.
> - Do we need to consider inline PGP? That is, have the encrypted part you want to leak in the main body?
inline PGP and also html content inside the encrypted parts may trigger issues.
REPOSITORY
R94 PIM: Message Library
REVISION DETAIL
https://phabricator.kde.org/D20757
To: knauss, #kde_pim, aacid, dfaure
Cc: vkrause, kde-pim, dvasin, rodsevich, winterz, mlaurent, knauss, dvratil
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kde.org/pipermail/kde-pim/attachments/20190423/c4804c80/attachment.html>
More information about the kde-pim
mailing list