Version: 1.6.50 (CVS 20040117) (using KDE Devel) Installed from: Compiled sources Compiler: gcc-3.3.1-29 OS: Linux The following eMail-Code caused KMail to open the attachment (winmail.dat) in KOrganizer without asking. This could be a possibility to execute code on a machine with the user's priviliges. Please don't be confused that this is an eMail with a Symantec Virus Notification... //----------------- EMail-Code -------------------------------- Return-Path: <someuser@t-online.de> X-Flags: 1001 Delivered-To: GMX delivery to christian.weickhmann@gmx.de Received: (qmail 9537 invoked by uid 65534); 30 Jan 2004 15:06:29 -0000 Received: from mailout08.sul.t-online.com (EHLO mailout08.sul.t-online.com) (194.25.134.20) by mx0.gmx.net (mx010) with SMTP; 30 Jan 2004 16:06:29 +0100 Received: from fwd03.aul.t-online.de by mailout08.sul.t-online.com with smtp id 1AmYBD-0001Wf-02; Fri, 30 Jan 2004 13:55:27 +0100 Received: from someuser (V8Fl6TZTgeUu1U4Eb3gE6EylaZ95cRqcVN7pw1soU1OUatriwkMs6E@[80.128.190.27]) by fwd03.sul.t-online.com with esmtp id 1AmY91-1sb0j20; Fri, 30 Jan 2004 13:53:11 +0100 From: someuser@t-online.de (Someone) To: "Weickhmann, Christian" <christian.weickhmann@gmx.de> Subject: WG: Norton AntiVirus News Bulletin - Virus Alert! Date: Fri, 30 Jan 2004 13:52:02 +0100 Message-ID: <NIBBINLBKLHABIDBJLODMEDDCDAA.wiener.helga@t-online.de> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_NextPart_000_000B_01C3E738.3D67BF20" X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2911.0) X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2800.1106 Importance: Normal X-MS-TNEF-Correlator: <NIBBINLBKLHABIDBJLODMEDDCDAA.wiener.helga@t-online.de> Disposition-Notification-To: "Someuser" <someuser@t-online.de> X-Seen: false X-ID: V8Fl6TZTgeUu1U4Eb3gE6EylaZ95cRqcVN7pw1soU1OUatriwkMs6E X-GMX-Antivirus: -1 (not scanned, may not use virus scanner) X-GMX-Antispam: 0 (Mail was not recognized as spam) Status: R X-Status: N X-KMail-EncryptionState: X-KMail-SignatureState: X-KMail-MDN-Sent: This is a multi-part message in MIME format. ------=_NextPart_000_000B_01C3E738.3D67BF20 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 8bit Hallo Christian, [...] Some eMail-text. -----Ursprüngliche Nachricht----- Von: NAV-Techinfo [mailto:symantec_bulletins@symantec.com] Gesendet: Dienstag, 27. Januar 2004 19:51 An: NAV-TECHINFO-L@excu-ls-1.symantec.com Betreff: Norton AntiVirus News Bulletin - Virus Alert! January 27, 2004 _____________________________ In this issue: 1. Level 4 Virus Alert! W32.Novarg.A@mm 2. Feedback 3. Subscribing and unsubscribing 4. Disclaimer _____________________________ NOTE: This is an outgoing email address. Do not reply to this email message. If you require assistance with installing, configuring, or troubleshooting a Symantec product, or if you have a question for Customer Service, then visit the Symantec Service & Support Web site at the following Internet address: http://www.symantec.com/techsupp/ To view this and prior News Bulletins in HTML format, visit the following Internet address: http://www.symantec.com/techsupp/bulletin/archive/nav/nav_archive.html _____________________________ 1. Level 4 Virus Alert! W32.Novarg.A@mm Security Response is currently tracking a new mass-mailing worm named W32.Novarg.A@mm. The threat arrives in an email with an attachment that has an .exe, .pif, .scr or .zip file extension. This worm is encrypted. Note: Symantec Consumer products that support Worm Blocking functionality automatically detect this threat as it attempts to spread. The following write-up will be updated when additional information about the worm is available. Check the write-up frequently for updated information. http://www.symantec.com/techsupp/vURL.cgi/nav119 Definitions dated January 26, 2004 will detect the W32.Novarg.A@mm worm. Run LiveUpdate or download the Intelligent Updater virus definitions at: http://securityresponse.symantec.com/avcenter/defs.download.html Symantec Security Response has developed a removal tool to clean the infections of W32.Novarg.A@mm. You can download the removal tool from the Symantec Web site at: http://www.symantec.com/techsupp/vURL.cgi/nav120 Also Known As: W32/Mydoom@MM [McAfee], WORM_MIMAIL.R [Trend] Type: Worm Infection Length: 22,528 bytes Systems Affected: Microsoft Windows 95/98/Me/NT/2000/XP Systems Not Affected: DOS, Linux, Macintosh, OS/2, UNIX, Microsoft Windows 3.x _____________________________ 2. Feedback Do you have feedback that can help us provide better products or services? If so, then we want to hear from you. Visit the Symantec suggestion box at the following Internet address, and let us know how we can improve: http://www.symantec.com/feedback/ _____________________________ 3. Subscribing and unsubscribing You are receiving this email because you subscribed to the Norton AntiVirus Technical News Bulletin from the Symantec Web site. If you want to subscribe to other Symantec newsletters, or you want to unsubscribe, then follow the instructions at the following Internet address: http://www.symantec.com/techsupp/bulletin/consumer.html If you are unable to successfully unsubscribe, then follow these steps: 1. Create a new email message addressed to: LISTSERV@LSERVER.SYMANTEC.COM 2. In the Subject line, type the following: UNSUBSCRIBE 3. In the body of the message, type the following: SIGNOFF NAV-TECHINFO-L 4. Send the message. _____________________________ 4. Disclaimer THIS DOCUMENT IS PROVIDED FOR INFORMATIONAL PURPOSES ONLY. This message contains Symantec Corporation's current view of the topics discussed as of the date of this document. The information contained in this message is provided "as is" without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability, fitness for a particular purpose, and freedom from infringement. The user assumes the entire risk as to the accuracy and the use of this document. This document may not be distributed for profit. Symantec and the Symantec logo are U.S. registered trademarks of Symantec Corporation. Other brands and products are trademarks of their respective holder(s). (c) Copyright 2003 Symantec Corporation. All rights reserved. Materials may not be published in other documents without the express, written permission of Symantec Corporation. ------=_NextPart_000_000B_01C3E738.3D67BF20 Content-Type: application/ms-tnef; name="winmail.dat" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="winmail.dat" eJ8+IgIMAQaQCAAEAAAAAAABAAEAAQeQBgAIAAAA5AQAAAAAAADoAAEIgAcAGAAAAElQTS5NaWNy b3NvZnQgTWFpbC5Ob3RlADEIAQ2ABAACAAAAAgACAAEIAAUABAAAAAAAAAAAAAEJAAQAAgAAAAAA AAABBoADAA4AAADUBwEAHgANADMAAAAFAD8BAQOQBgAoEwAAJgAAAAsAAgABAAAACwAjAAAAAAAD ACYAAAAAAAsAKQABAAAAAwAuAAAAAAACATEAAQAAABgBAABQQ0RGRUIwOQABAAIAgQAAAAAAAAA4 obsQBeUQGqG7CAArKlbCAABQU1RQUlguRExMAAAAAAAAAABOSVRB+b+4AQCqADfZbgAAAEM6XFdJ TkRPV1NcTG9jYWwgU2V0dGluZ3NcQW53ZW5kdW5nc2RhdGVuXE1pY3Jvc29mdFxPdXRsb29rXG91 dGxvb2sucHN0ABgAAAAAAAAAq5BlhT412BGNsQDgfbSl1sKBAAAAAAAAGAAAAAAAAACrkGWFPjXY EY2xAOB9tKXWwoAAABAAAACWLfavlHi7T4zY26jz8URtMgAAAFdHOiBOb3J0b24gQW50aVZpcnVz IE5ld3MgQnVsbGV0aW4gLSBWaXJ1cyBBbGVydCEAAwA2AAAAAAAeAE0AAQAAAAEAAAAAAAAAHgBw AAEAAAAuAAAATm9ydG9uIEFudGlWaXJ1cyBOZXdzIEJ1bGxldGluIC0gVmlydXMgQWxlcnQhAAAA AgFxAAEAAAAWAAAAAcPnL9j0LlG2f2wjRE2YScbBpg0KtwAACwAXDAAAAAACAR0MAQAAAB4AAABT TVRQOldJRU5FUi5IRUxHQUBULU9OTElORS5ERQAAAAsAAQ4AAAAAQAAGDgCSCLYv58MBAgEKDgEA AAAYAAAAAAAAAKuQZYU+NdgRjbEA4H20pdbCgAAACwAfDgEAAAACAQkQAQAAAOcNAADjDQAAQhkA AExaRnVKQ2u4AwAKAHJjcGcxMjXyMgD7MzYB6AKkA+MCAARjaArAc2V0MCCbBxMCgH0KgAjIIDsJ by0OMDUCgAqBdgiQd2tpC4BkNAxgYwBQCwNjywBBC2BuDhAwMwBQC7WMIEgHQAkAIENoBRDkc3QH MG4sCqIKhAqAERdRIERlC4AgWmVMdWcDAAQgZ3UFQGE4dXNnARAW0QnwPyCSTwSBIG0McCdkAYDN GLB1GLAN4GggBJAYkdhkYXYCIBvhaAbwGmGVF8pOANBoF2BlaAnwvwEABdALcAMgHKEIkGwFQLEb sS4gSRvBENBiHpA/GNEaIBvBAMAe4RjhTGlydh6QVXAcQB4wGYBldQDBaAVAdRSgHDAJ8Gv8ZSwc MRsSHDAIkAYBEMDTHpAcQG1pBUBrC2AFwMUXUS4XykluegPxJCHHA6AgExuyMiBQA2ACYKkiMGU6 F8oxH7BNGNF9HpBBDcIicSGAHAEbEGV4NHJrBUApciM3JIJPExmgCQBvaxvgdHdh+wQgGiB1AyAl EhawGSAh8T5sCJAbEiBBBCApciB6/yKgKiIeAhmACsEDACJiF2BjCsAeMG4uRQSgGJFu6yCjHkBy IOFpIiERQBngxyZhB0AwQSAoUiKgHjDuchogFzAJ8Ckthi4XGNEfLFAUoANQGNADMCdmNmcBICkg MGAgRQuAIOJn2QuAZyAgMDVAVhvxFODPLoI1WCLRBcBQQxnCMqAdB5FrJHAksAhwejog1CJTI9Fr NWJuOCQDoLU4oWoREHoZszImIijU/RiSdSMwG3E6RR4wHBMvkD5vEMAg4ixSIkIaYmV2/yvQH7Ar tikgG4A8shbRCJH1HP0yH7BHPfEEkiAhIrH+dwbwMmEnAxjSJMApAgQgjkUsQxjhOuJVU0Iv8f8F kCMQBcBF5BegPiIZ0COj9xEAMdBE1EIDEBqyAJAUoN8fsBugR4EEIEKAcioiJKH/AHAy4ScDL6M1 8QIwGgAaANs4RDHyYRoAOFNCB5AkkP56BnEDoCnRFbIh8QeRMOPbKQIx0FQ1ISAwciMxJpHfLiI3 UR4wIzA7UGQ+cS+VOxogSMJICJElAhnAbHP/FwAcQAQQH0AgMQRyIRMqIvxobi2QJCEEICd1PtAj 0Xc20gEAMdBLMCMaUBEAcv0fsEZJkRCxGsE2g1JALFI/NKkfsB3iGLMawRjALS/XJhBA4yHgaRxx ZiKgKnD/WiEIkRwiV6Mgk0q0F8pVoP86kDzTG5EvgT51VpJPIRpQ90txIzBDYHIDkVsyLZFLctc9 dxqATLB6VpJnU/JHVO9IFhoASZQHkW1WkhsTJvTuYgdAIsApA0w1YjdANqH/IBJGwgnwA6Abshr0 TfcbEf1eonRfcBmQNqFMc0hERyL/B4ApETsDUkEmYSkgFuBU0/1jYjZhhC6gVoNGEBoAQxHtJUtW HzEmkUQAcCwQB3BfKcBfYRngJUstMGwvYCC+VwiQWREXyhVhETAtcVL6VRDwcFaDFdBT81iDBRAf ImFxU20FAiA50E5BVrwtVAWQHyAggBcAWwDA4QMQdG86cwbAAHBF8bxfYiywGlAXcACAQHWWci4F oG1dF8RCgR5idJc50EkBQNJnIzAyNx+wGkoAcHUKwQHQMDQg8DE5OjUVAwqAKVB0JQBFQ0hJTkZP LYBMQGV4Y3UtUjD+LSjAdsoXxEywaAABEXQh3wkRHHEpUBdwbWByOOEHwd9IEXY1cUA3AH8jQRpQ ACDuIXBLF9N5dHl5IXkRefGdF8Rfg7+EeSW2IHQfIH9FEQQQClAn/iFQP6AfQCC3ehCAem/QM0JQ fmB2CsDgZy5BQG19ZUJRVmBdCeBkZGBGEBfEM4eRU/R1YgTyYjaSNOEikTdA+4vnF8Q0h5EboATw C2EHgG9wNYR/hM8d0E97YDnQVM+GJIxxUvAZoGdvNpIiMfEDEWFkZAlwBBBI4RcA/z5gBUAJcAtQ grB1YIYEkwPfF8QHgUwiH7EjoHkIYJRRfHF1XcAekFKBF1EAcGP/HpAD8IYQQLcV0CMwBaAggP8x oAhxmPIFsBfEaAAIYCehvnMcwJQwjEMGAHWlIHHQ+wRwFOB0meIfcJaUENAhgd8+QJcQPfFaIwWx QxngdWD/jqcGYRRAl/AjMIYQJpEUQE9M0aACm5ifhSAmi7Fw/nAJEW/QbFAqkSHxIeCgAv8XxAIQ FuED8DahJhBCshEQB5NWJ/sicHRwOi8vdnem4HyrL0XxHhCiQS/9F8pUFwAUQoYEjIJx0FoghwXA f3tFE0hUTUyeUv8AwJyRoGikByW2pM+l36bvu6f3diYvCsB0oSGALzDgqnazEl+ypS4icG2Vhf+P /5BPhx+IL4k/GAYGYHww9QUQdIKwUgeQomAAgCbx/wQgurEzUSvQlKFfcEYQm0TvKSAH4ADABBAt dSI2kl9R/zHQMOAHgAsxF+K47bdhkcD/HpCGEAlwo0EKwAUQIYBFE/8DkZMEmCMDkSHgAZA+gbwh 34YBIeCvpSxhA5EufBAjITwucAaQxNEE8ZyyLnrvBSAsgAMQIEF4MEEAkAIg/8AzGWG+Q5USl+CC oAUwCYD/JUt+YB4wOdCbpwhQjNGOob+cJgQgw4JP0aJVvlJCCQD/vLRaYZyAWiExgbrwF8QZ0Pue 0VoBYxbRgrB4QQWQoKL/GWHApkURGbECQCIwBTDLUb9qIXHQwNDIjMBipAh3utH/WWCiQFTRapEg MaJAIdJDQf8mgpNhJJDNc0CxrCRaIgGg/5JxmiUkMceGHFAewQGgGlD/H7AXIEYBoLPTlzURndG8 M3+eYtSlGCXWOCVLsA+njna4VVJMd0A2gLMSMXow/xfKGMCZYAMAWhIEINTEglf+NoL01BTPNx6Q uO2+MyVFvzLBF8QhYiG1BbFQgHdT4P5vk2Cgs64yQRFLcQVAIbT/BcAUQH8yAQHhZyHgrz/dsf8R ALq0k5G7U94cHFCX8DLi/i8BAW6g54a0GZ8loRi6vufEIgEAt7FvcNTxPkAJcP8EYIlwAyB1YAbw lLKOYMDQ34Xyo5Ugcc9h4aNvI6C/T/5ZlsHO0DhB55rzGwNSo2j/m6eiuerf3b/ez9/WDAEX2fuA 0FJBSz5g56ARQK8gt3AxuOEvTXlQgANwQE0iTXUATWNBLfBlXQEjMFdPUk1fTUnoTUFJ37BSdQBO 4RSg/XeFVMhAyZHMMyW29SW3gUVNsWgAkTIyLA5AON02wHk94fAGHiFtgLF+IPfj4QmAAJFNDeCa kFJAG0EPb+AUoFdwxEA5NS85RjgA8LMATlQveeEwOC9YUAb8yWEHykRPblMjMCFgeZB4IzAesGN/ gCB1YJrwIzAMsApQIzBVuE5JWA1BCJ6LJngXyv+1j7XfQeiKneDVFwCdJwHh74rTy2T3Mh5QbMYA OOGcMf/pkB6BIDDQ0crJqoFWIZ+y3nMdFZaBUkCf9XeYAcnx/5SyHlAk4fkTnSEfsG1goI/dN0Bn S1CeBNbweKMx1zi/pA+upyMwjIJ2URdiawAh/yawIhEbAfcybiAXooas/A//p4UWBqh7Ef8ST8j1 i4+Mn//IufbyL3D4Ipfws+A2kpT4/zbBztBMAHKQnSIq9tTxlMP/cpF+fajldJFKsV5Bf3z5Fv+b mKK2XEuWhRs2LveUspQw91bSm6e9MXN2UUKxIRGqgf81mbb0Ktif5h+EoLNAwn8w//VFo0Qff3hQ zfWu3yQf/P//sgiZMcqD71+WhSyiaEDYov82FGwQk6FaYM7yOi87OfHhvQdxcD8cBhAGELdSQ8DC /52SvTKTBJX1k1Yvc0iPSVIATElTVFNFUlaMQExN0k3gLlNZArDDCjB7cC5DT01InhPC94XjoOEp 4Grj4pjRRuIEAQ+s/ExPSVIOcFNVQlPgQ1JJQkVInimSUKX91vBk4rD1saDClfVR31LvkU0VU0lH kWBGRnsd/0iejfLw8CFRV0nImyfPKB8vyPWN/6i4e5BTDJFDVRxNRQowlnBjUFBST+BWSURFRIqQ AlCWcMN7sQJgQVRJT3RArABqUN+QUAywRWNQZZBM/lnR7ZHhSwaZMcLwq2LJyfZyomHcUye7x6lk VxV1YP3FAGMG5dWQYeCesEvi0GH/VxXnBFcikeEBIHwwwzKWYP/AYtYqaFXU8YAg1zZnqZHhyxel IWAi0GJzIpgT1wF/GyG8AMnxVvPJ8OKwvMFk/5ygLRA3Mky0fBDRkUvTnMK/0QDooAxQnKCAII5g ddWQ35LRshCuoJQi6KBtowEvh/92pXOmqYAG5fWxjqGzwMnx30TwveHxUJygmWB0UbC9kL+eU52w XqHOsUXwG9FwmZD/omDx4CEk2jEMUPkx+RLbl/+ZopMAbrcucXyhhnGV8aCz97whlzLZsHMWcNBh L6XDAP+6scMA4rAqkqN3LnJt75G0/25mvWHisJQiNsFsUZqAKjD/1xDU8Z5inDF8Acibm6eDpe+b mB+wkqAsk1VOkJZg+EB/3+AHcfhA5/G8kOnwkxByvmv1k5umTLRpeZZgTzcz+mJz4WSp9ssFLKKM zKAR/5cwlFHxoPUynYA/lT1A6fAQcihzKcibKGMpvcpBcOyA6LBDIOMCM2jf/470/8DUUJVTxEA+ 4aGhyHH7DVEgQWnNoGexhsBMtIb1/32Q2LCMQEfgcII3FW5mx2H/c0WBc3XkOMDTksaRfNAgUL94 cL2QBWF6Z5YP3Hh9XtACAKEQAAsAAYAIIAYAAAAAAMAAAAAAAABGAAAAAAOFAAAAAAAAAwADgAgg BgAAAAAAwAAAAAAAAEYAAAAAEIUAAAAAAAADAAeACCAGAAAAAADAAAAAAAAARgAAAABShQAAfW4B AB4ACYAIIAYAAAAAAMAAAAAAAABGAAAAAFSFAAABAAAABAAAADkuMAALAA2ACCAGAAAAAADAAAAA AAAARgAAAACChQAAAQAAAAsAOoAIIAYAAAAAAMAAAAAAAABGAAAAAA6FAAAAAAAAAwA8gAggBgAA AAAAwAAAAAAAAEYAAAAAEYUAAAAAAAADAD2ACCAGAAAAAADAAAAAAAAARgAAAAAYhQAAAAAAAAsA boAIIAYAAAAAAMAAAAAAAABGAAAAAAaFAAAAAAAAAwBvgAggBgAAAAAAwAAAAAAAAEYAAAAAAYUA AAAAAAACAfgPAQAAABAAAACrkGWFPjXYEY2xAOB9tKXWAgH6DwEAAAAQAAAAq5BlhT412BGNsQDg fbSl1gIB+w8BAAAAgQAAAAAAAAA4obsQBeUQGqG7CAArKlbCAABQU1RQUlguRExMAAAAAAAAAABO SVRB+b+4AQCqADfZbgAAAEM6XFdJTkRPV1NcTG9jYWwgU2V0dGluZ3NcQW53ZW5kdW5nc2RhdGVu XE1pY3Jvc29mdFxPdXRsb29rXG91dGxvb2sucHN0AAAAAAMA/g8FAAAAAwANNP03AAACAX8AAQAA ADgAAAA8TklCQklOTEJLTEhBQklEQkpMT0RNRUREQ0RBQS53aWVuZXIuaGVsZ2FAdC1vbmxpbmUu ZGU+AAMABhDbXPlNAwAHEBwRAAADABAQAAAAAAMAERABAAAAHgAIEAEAAABlAAAASEFMTE9DSFJJ U1RJQU4sSVNUREVJTlpFVUdOSVNHVVRBVVNHRUZBTExFTj9PREVSTVXfVERVRElDSEVSU1REQVZP TkVSSE9MRU4/TkFDSFNURUhFTkRFTUFJTEVSSElFTFRJQwAAAAAS3A== ------=_NextPart_000_000B_01C3E738.3D67BF20-- //---------------End of eMail ---------------------------------
Neither KOrganzir nor KMail (nor any other KDE application) will execute any code without asking the user for confirmation. That this ms-tnef file is opened with KOrganizer is part of the groupware functionality. We'll look into this.
Having it autoload 'every' time I had the email show is pretty annoying. It takes time to open the software, yet it didn't seem to accomplish anything in particular with that time. At the very least, an option to not autoopen attachments, or anything related to them, would be greatly preferred. What was the file supposed to be capable of normally when autoopened? Is there a reason why kmail loads a program based on an attachment on its own in the first place?
Bug #79771 is similar.
This is actually a dup of 79771. I have submitted a patch which I hope will be committed prior to the 3.3 release.
*** This bug has been marked as a duplicate of 79771 ***