[Bug 311158] Attachment properties dialog doesn't understand "filename" attribute

Bernd Oliver Sünderhauf pancho.mz at riseup.net
Wed Dec 5 09:16:39 GMT 2012


https://bugs.kde.org/show_bug.cgi?id=311158

--- Comment #4 from Bernd Oliver Sünderhauf <pancho.mz at riseup.net> ---
Created attachment 75633
  --> https://bugs.kde.org/attachment.cgi?id=75633&action=edit
another test case regarding aspect #3

Regarding aspect #3, the case of contradicting filename and name properties,
here's a second test case: filename says "dangerouscode.doc", while name says
"justsome.txt". Now,
- Enterprise or fancy headers pretends "justsome.txt" and shouldn't
- Editing the message pretends "justsome.txt" and shouldn't
This is security-relevant just because the file is correctly saved to
"dangerouscode.doc"
Other places seem to be fine.

The case of contradicting MIME headers and filename extensions might also be
security relevant, but is not subject of this bug ticket.
Finally, aspect #4 should be split off to a separate ticket.

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the Kdepim-bugs mailing list