[kmail2] [Bug 404698] Decryption Oracle based on replying to PGP or S/MIME encrypted emails

Jens Mueller bugzilla_noreply at kde.org
Tue Apr 9 16:41:27 BST 2019


https://bugs.kde.org/show_bug.cgi?id=404698

--- Comment #4 from Jens Mueller <jens.a.mueller+kde at rub.de> ---
Things may have changed in the meantime, but for the version we tested
(v5.2.3), there is no need to click on "Decrypt Message". While the plaintext
is not shown to the user, if he does not explicitly click "Decrypt Message",
the plaintext is still included in replies -- just re-tested for S/MIME and
PGP/MIME. Note that KMail was tested in the default settings (the option
"Attempt decryption of encrypted messages when viewing" was *not* set).

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the Kdepim-bugs mailing list