[Bug 290783] New: KMail uses invalid sender when using "edit message" at a message not sent by me.
Ingo Stierand
stierand at informatik.uni-oldenburg.de
Fri Jan 6 10:27:39 GMT 2012
https://bugs.kde.org/show_bug.cgi?id=290783
Summary: KMail uses invalid sender when using "edit message" at
a message not sent by me.
Product: kmail2
Version: 4.7
Platform: openSUSE RPMs
OS/Version: Linux
Status: UNCONFIRMED
Severity: normal
Priority: NOR
Component: general
AssignedTo: kdepim-bugs at kde.org
ReportedBy: stierand at informatik.uni-oldenburg.de
Version: 4.7 (using KDE 4.7.4)
OS: Linux
I wanted to get the recepients of an existing email to create a new message.
The original mail wasn't sent by me. The easiest way to get this was to use the
"edit message" action. Doing so I got the composer, edited the message
(including modifications of the recepient list, and the subject line) and sent
the 'new' message. But surprisingly the 'new' message got the old sender in the
'from' field of the original message.
I consider this as a bug. However, it is at least a security issue when I can
fake a sender with a nice user-level GUI app.
Reproducible: Always
Steps to Reproduce:
1. Take a message you haven't sent but received.
2. Use 'T' to edit the message (or via menu 'Message-Edit').
3. Edit the message.
4. Send the message.
Actual Results:
Looking at the source code of the newly created message you will find the
sender of the original message in the from field.
Expected Results:
The 'from' field of any message sent by me should always contain a valid
mail-address that matches one of my identities.
OS: Linux (i686) release 3.1.0-1.2-desktop
Compiler: gcc
--
Configure bugmail: https://bugs.kde.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
More information about the Kdepim-bugs
mailing list