Bug 289732 - Unwanted information disclosure: Bcc-addresses are sometimes retained in sent mails
Summary: Unwanted information disclosure: Bcc-addresses are sometimes retained in sent...
Status: RESOLVED DUPLICATE of bug 263587
Alias: None
Product: kmail2
Classification: Applications
Component: general (show other bugs)
Version: 4.7
Platform: Ubuntu Linux
: NOR normal
Target Milestone: ---
Assignee: kdepim bugs
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-12-24 12:07 UTC by Gunter Ohrner
Modified: 2011-12-25 13:18 UTC (History)
1 user (show)

See Also:
Latest Commit:
Version Fixed In: 4.7.4


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gunter Ohrner 2011-12-24 12:07:22 UTC
Version:           4.7 (using Devel) 
OS:                Linux

Apparently, kmail does not always filter out Bcc addresses from sent mails. I just found out the hard way when sending christmas greetings to a bunch of friends. :-/ Pretty embarassing. :-(



Reproducible: Sometimes

Steps to Reproduce:
Send a mail containing receipients in the Bcc field.

Actual Results:  
Sometimes, the Bcc field is not cleaned / emptied and all receivers will get hold of all target addresses... :-/

Expected Results:  
The Bcc field should by emptied or removed.


The following is an example message from me to myself, with all mail-addresses only slightly altered for spam protection reasons:

Return-path: <Gunter - at - ohrner.net>
Envelope-to: go - at - ohrner-it.com,
 gunter - at - ohrner.net
Delivery-date: Sat, 24 Dec 2011 12:46:27 +0100
Received: from xdsl-87-78-109-156.netcologne.de ([87.78.109.156] helo=zweiblum.localnet)
	by luggage.ohrner.net with esmtpsa (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32)
	(Exim 4.69)
	(envelope-from <Gunter - at - ohrner.net>)
	id 1ReQ3X-00039H-10; Sat, 24 Dec 2011 12:46:27 +0100
From: Gunter Ohrner <Gunter - at - ohrner.net>
To: gunter - at - ohrner.net
Bcc: Gunter Ohrner <go - at - oecher-netz.de>, Gunter Ohrner <go - at - ohrner-it.com>, Gunter Ohrner <go - at - relaix.net>, go - at - uni-dsl.de
Date: Sat, 24 Dec 2011 12:46:20 +0100
Message-ID: <36804546.mCpMsNUWHZ - at - zweiblum>
Organization: Gunter Ohrner Datensysteme
User-Agent: KMail/4.7.4 (Linux/3.0.0-14-generic; KDE/4.7.4; x86_64; ; )
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="iso-8859-1"
X-Orig-fvyLszf-Subject: Test mit BCC
Subject: Test mit BCC
X-DSPAM-Result: Whitelisted
X-DSPAM-Processed: Sat Dec 24 12:46:27 2011
X-DSPAM-Confidence: 0.9992
X-DSPAM-Improbability: 1 in 127601 chance of being spam
X-DSPAM-Probability: 0.0000
X-DSPAM-Signature: 4ef5bb93121141026813322
X-DSPAM-Factors: 27,
	From*Ohrner, 0.00034,
	From*Gunter+Ohrner, 0.00048,
	Organization*Ohrner, 0.00056,
	Organization*Gunter, 0.00056,
	Organization*Ohrner+Datensysteme, 0.00056,
	Organization*Gunter+Ohrner, 0.00056,
	Organization*Datensysteme, 0.00056,
	)+PGP, 0.00058,
	by+AudioScrobbler, 0.00058,
	AudioScrobbler, 0.00058,
	AudioScrobbler+>, 0.00058,
	bei+eMails, 0.00058,
	0x1128F25F, 0.00058,
	Url*fm/user/Interneci/, 0.00058,
	PGP+0x1128F25F, 0.00059,
	Received*from+<Gunter, 0.00060,
	Return-path*<Gunter, 0.00060,
	From*<Gunter, 0.00061,
	From*Ohrner+<Gunter, 0.00061,
	From*<Gunter+ohrner.net>, 0.00061,
	From*Gunter Ohrner <Gunter - at - ohrner.net>, 0.00061,
	Received*<Gunter+ohrner.net>), 0.00061,
	Return-path*<Gunter+ohrner.net>, 0.00061,
	Verschlüsselung, 0.00072,
	Verschlüsselung+bei, 0.00073,
	eMails+erwünscht, 0.00073,
	erwünscht+), 0.00073

Test mit BCC
--=20
*** Powered by AudioScrobbler --> http://www.last.fm/user/Interneci/ **=
*
12:27 | Quarks & Co - 08.11.2011, Menschen auf der Autobahn
10:05 | Ayreon - Web Of Lies
09:50 | Ayreon - Ride The Comet
09:43 | Ayreon - Newborn Race
*** PGP-Verschl=FCsselung bei eMails erw=FCnscht :-) *** PGP: 0x1128F25=
F ***
Comment 1 Laurent Montel 2011-12-24 13:08:51 UTC
Fixed in 4.7.4
Comment 2 Gunter Ohrner 2011-12-25 09:52:37 UTC
Will this fix also be included in 4.8, or was the bug not present in this version?
Comment 3 Christophe Marin 2011-12-25 13:18:39 UTC

*** This bug has been marked as a duplicate of bug 263587 ***