[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-06-17 Thread Christophe Giboudeaux
https://bugs.kde.org/show_bug.cgi?id=394554 Christophe Giboudeaux changed: What|Removed |Added CC||axel.br...@gmx.de --- Comment #20 from

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-26 Thread Volker Krause
https://bugs.kde.org/show_bug.cgi?id=394554 Volker Krause changed: What|Removed |Added Latest Commit||https://commits.kde.org/mes |

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-24 Thread Gunter Ohrner
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #18 from Gunter Ohrner --- (In reply to Christophe Giboudeaux from comment #15) > Did you load external references for another message in the same folder > before reading this one ? > > OK, I can reproduce something weird with master: > >

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-24 Thread Volker Krause
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #17 from Volker Krause --- Possible fix: https://phabricator.kde.org/D13096 -- You are receiving this mail because: You are watching all bug changes.

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-24 Thread Christophe Giboudeaux
https://bugs.kde.org/show_bug.cgi?id=394554 Christophe Giboudeaux changed: What|Removed |Added Ever confirmed|0 |1 Status|UNCONFIRMED

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-24 Thread Christophe Giboudeaux
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #15 from Christophe Giboudeaux --- Did you load external references for another message in the same folder before reading this one ? OK, I can reproduce something weird with master: in folder X, I loaded external references for one email,

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-24 Thread Gunter Ohrner
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #14 from Gunter Ohrner --- Ok, it really gets somewhat strange now: * I got an HTML mail (again some GDPR notification from a company) and kMail rendered the externally referenced logo immediately after activating HTML rendering. * Afterwar

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-24 Thread Gunter Ohrner
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #13 from Gunter Ohrner --- (In reply to Gunter Ohrner from comment #12) > However, with the example message I attached, I was never asked. The image > was displayed immediately when opening the message for the first time and > chosing "rende

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-24 Thread Gunter Ohrner
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #12 from Gunter Ohrner --- (In reply to Volker Krause from comment #11) > One thing I noticed during testing this is that once you loaded external > references for an email, the next display of HTML content without confirming > loading exter

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-24 Thread Volker Krause
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #11 from Volker Krause --- One thing I noticed during testing this is that once you loaded external references for an email, the next display of HTML content without confirming loading external references can be served from the web engine ca

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-23 Thread Gunter Ohrner
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #10 from Gunter Ohrner --- Created attachment 112825 --> https://bugs.kde.org/attachment.cgi?id=112825&action=edit Message with which I can reproduce the behaviour. kMail will show the image referenced in the attached message file as soon

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-23 Thread Gunter Ohrner
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #9 from Gunter Ohrner --- Addendum: This menu entry is in the same state (unchecked, but greyed-out) for the other folder in which external references are *not* loaded automatically. I cannot see any difference in the GUI between those two.

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-23 Thread Gunter Ohrner
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #8 from Gunter Ohrner --- Created attachment 112823 --> https://bugs.kde.org/attachment.cgi?id=112823&action=edit "Load external references" entry in "Folder" menu for folder in question This entry is disabled (greyed-out) for the folder

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-22 Thread Volker Krause
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #7 from Volker Krause --- It's in the main menu: Folder > Load External References -- You are receiving this mail because: You are watching all bug changes.

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-22 Thread Gunter Ohrner
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #6 from Gunter Ohrner --- Mh, maybe I'm doing something stupid, but I still don't know what. Apparently, this does not happen in all folders, but it does happen in my Inbox folder. I didn't knowingly switch any setting, and it definitely wo

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-22 Thread Volker Krause
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #5 from Volker Krause --- That would be a very serious security issue obviously, but I can't reproduce this here either. Besides the global setting, there is a per-folder setting for this (Folder -> Load External References). Is that also s

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-22 Thread Christophe Giboudeaux
https://bugs.kde.org/show_bug.cgi?id=394554 Christophe Giboudeaux changed: What|Removed |Added CC||vkra...@kde.org -- You are receiving t

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-22 Thread Christophe Giboudeaux
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #4 from Christophe Giboudeaux --- Created attachment 112813 --> https://bugs.kde.org/attachment.cgi?id=112813&action=edit html email from indeed Can't reproduce locally, tcpdump also shows no traffic if the external references aren't load

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-22 Thread Gunter Ohrner
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #3 from Gunter Ohrner --- Created attachment 112810 --> https://bugs.kde.org/attachment.cgi?id=112810&action=edit kMail security configuration kMail configuration pane showing the disabled "external references" checkbox. -- You are rece

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-22 Thread Gunter Ohrner
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #2 from Gunter Ohrner --- Created attachment 112809 --> https://bugs.kde.org/attachment.cgi?id=112809&action=edit HTML mail from indeed.com Yes, every HTML mail with external image references I tested before opening this issue. See attach

[kmail2] [Bug 394554] Regression: kMail 5.8.1 Information Leak: kMail loads external references in HTML mails without asking

2018-05-22 Thread Christophe Giboudeaux
https://bugs.kde.org/show_bug.cgi?id=394554 --- Comment #1 from Christophe Giboudeaux --- "seems to load" or you have any evidence/test message or anything showing the issue you report ? -- You are receiving this mail because: You are watching all bug changes.