D20757: Test mails for Decryption Oracle based on replying to PGP or S/MIME.

Sandro Knauß noreply at phabricator.kde.org
Tue Apr 23 15:04:42 BST 2019


knauss added a comment.


  In D20757#454735 <https://phabricator.kde.org/D20757#454735>, @vkrause wrote:
  
  > This makes sense I think (and should go in IMHO), but I'm not sure if it is complete to cover all of bug 404698.
  >
  > - Do we need to be concerned about forwarding (which does include attachments AFAIK)?
  
  
  make sense, yes.
  
  > - Do we need to consider inline PGP? That is, have the encrypted part you want to leak in the main body?
  
  inline PGP and also html content inside the encrypted parts may trigger issues.

REPOSITORY
  R94 PIM: Message Library

REVISION DETAIL
  https://phabricator.kde.org/D20757

To: knauss, #kde_pim, aacid, dfaure
Cc: vkrause, kde-pim, dvasin, rodsevich, winterz, mlaurent, knauss, dvratil
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.kde.org/pipermail/kde-pim/attachments/20190423/c4804c80/attachment.html>


More information about the kde-pim mailing list