[kmail2] [Bug 404698] Decryption Oracle based on replying to PGP or S/MIME encrypted emails

bugzilla_noreply at kde.org bugzilla_noreply at kde.org
Wed Jun 12 15:59:32 BST 2019


https://bugs.kde.org/show_bug.cgi?id=404698

beuc at beuc.net changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |beuc at beuc.net

--- Comment #22 from beuc at beuc.net ---
Hi,

As part of the Debian LTS project, I'm trying to fix this vulnerability in
Debian Jessie, which ships kdepim 4.14.1.

I'm attempting to backport
https://commits.kde.org/messagelib/8f9b85b664be0987014c5d2485e706ab5a198e1b
but the API is very different, I'm not even sure there are available functions
to expose the MIME parts and extract their quotable content independently.

Do you think this is doable?

-- 
You are receiving this mail because:
You are the assignee for the bug.


More information about the Kdepim-bugs mailing list