Bug 278014 - CC recipient can see BCC recipients
Summary: CC recipient can see BCC recipients
Status: RESOLVED DUPLICATE of bug 263587
Alias: None
Product: kmail2
Classification: Applications
Component: general (show other bugs)
Version: 2.0.97
Platform: Debian testing Linux
: NOR normal
Target Milestone: ---
Assignee: kdepim bugs
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-07-18 13:15 UTC by Andreas Cord-Landwehr
Modified: 2011-08-25 15:10 UTC (History)
3 users (show)

See Also:
Latest Commit:
Version Fixed In:
Sentry Crash Report:


Attachments
Mail as received by To-receiver (who should not be aware of the Bcc receiver) (2.43 KB, text/plain)
2011-07-18 13:15 UTC, Andreas Cord-Landwehr
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Cord-Landwehr 2011-07-18 13:15:46 UTC
Created attachment 61959 [details]
Mail as received by To-receiver (who should not be aware of the Bcc receiver)

Version:           2.0.97 (using KDE 4.6.4) 
OS:                Linux

When I send a mail with following recipients:
To: Alice
Bcc: Bob
then it happens that Alice receives a mail from which she sees that I sent this mail as Bcc to Bob -- which is very bad/dangerous as I expect that Bob is a confidential recipient of which Alice should not be aware of!

If the bug type definition would not be that strict I would call this a critical bug.

Reproducible: Always

Steps to Reproduce:
A set up two mail accounts, created mail with one receiver, one Bcc-receiver and sent the mail. Both recipients could see both the To-receiver and the Bcc-receiver.


Expected Results:  
The To-receiver should not become aware of the Bcc receiver.
Comment 1 John King 2011-07-18 17:01:48 UTC
I cannot confirm this with kmail 2.1.96 on kde4.7RC2 from opensuse repositories. The To-receiver does not see the Bcc-receiver
Comment 2 Laurent Montel 2011-07-18 17:24:21 UTC
I can't confirm it.
Please update/retest and reopen this bug if necessary :)
Thanks
Comment 3 Christophe Marin 2011-07-18 17:30:42 UTC

*** This bug has been marked as a duplicate of bug 263587 ***
Comment 4 Christophe Marin 2011-07-18 17:33:21 UTC
From the pasted email:

User-Agent: KMail/4.6 rc2 (Linux/2.6.39-2-686-pae; KDE/4.6.4; i686; git-0441843; 2011-05-28)

Note that this version is quite old now.
Comment 5 roger.koot 2011-08-25 14:37:49 UTC
I can confirm the bug is still there.
OpenSuse 11.3-x86_64 KMail 4.7.0 using KDE 4.7.00, Qt-4.7.3

receiving parties can see the BCC'ed addresses in the header of the mail.
Comment 6 Laurent Montel 2011-08-25 15:10:38 UTC
Please send me an email, add a BCC in this email and I will look at if I see it.

Thanks