[telepathy] [Bug 313110] New: Magic character combination allows to write as the conversation-partner

Anton Kreuzkamp akreuzkamp at web.de
Fri Jan 11 23:27:37 GMT 2013


https://bugs.kde.org/show_bug.cgi?id=313110

            Bug ID: 313110
           Summary: Magic character combination allows to write as the
                    conversation-partner
    Classification: Unclassified
           Product: telepathy
           Version: git-latest
          Hardware: Compiled Sources
                OS: Linux
            Status: CONFIRMED
          Severity: normal
          Priority: NOR
         Component: text-ui
          Assignee: kde-telepathy-bugs at kde.org
          Reporter: akreuzkamp at web.de

Magic character combination ":\" allows to write as the conversation-partner.
Sounds like a injection to me. The bug might allow more critical injections.

Reproducible: Always

Steps to Reproduce:
1. Wait until your conversation partner has posted something
2. type ":\" (without quotes) and press Enter.
3. post something before your partner does so
Actual Results:  
":\" is not shown. The message sent afterwards is shown as if it was written by
your partner. The partner sees it the same way (as if it was written by
her/him) if she/he uses KTP as well, if she/he doesn't, the message is shown
normally, ":\" doesn't arrive.

Expected Results:  
The last two Entries in the Conversation list should be ":\" and your message.

Can be reproduced as well if the last message was something like "You are now
marked as Available". Then the message will be shown without any background. If
you write the magic combination if the last message was yours, the message will
normally be shown as yours.

-- 
You are receiving this mail because:
You are the assignee for the bug.



More information about the Kde-telepathy-bugs mailing list