kmail: CVE-2014-8878: Attachments are not encrypted when "automatic encryption" is selected"

Related Vulnerabilities: CVE-2014-8878  

Debian Bug report logs - #791800
kmail: CVE-2014-8878: Attachments are not encrypted when "automatic encryption" is selected"

version graph

Reported by: Daniel Hornung <daniel.hornung@ds.mpg.de>

Date: Wed, 8 Jul 2015 14:54:02 UTC

Severity: important

Tags: fixed-upstream, security, upstream

Found in version kdepim/4:4.14.1-1

Fixed in version 4:4.14.5-1

Done: Moritz Mühlenhoff <jmm@inutil.org>

Bug is archived. No further changes may be made.

Forwarded to https://bugs.kde.org/show_bug.cgi?id=340312

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, secure-testing-team@lists.alioth.debian.org, Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>:
Bug#791800; Package kmail. (Wed, 08 Jul 2015 14:54:06 GMT) (full text, mbox, link).


Acknowledgement sent to Daniel Hornung <daniel.hornung@ds.mpg.de>:
New Bug report received and forwarded. Copy sent to secure-testing-team@lists.alioth.debian.org, Debian/Kubuntu Qt/KDE Maintainers <debian-qt-kde@lists.debian.org>. (Wed, 08 Jul 2015 14:54:06 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Daniel Hornung <daniel.hornung@ds.mpg.de>
To: <submit@bugs.debian.org>
Subject: [kmail] Attachments are not encrypted when "automatic encryption" is selected
Date: Wed, 8 Jul 2015 16:17:17 +0200
[Message part 1 (text/plain, inline)]
Package: kmail
Version: 4:4.14.1-1
Severity: important
Tags: security
X-Debbugs-CC: secure-testing-team@lists.alioth.debian.org

--- Please enter the report below this line. ---

Sending OpenPGP/MIME encrypted emails with attachments does not encrypt the 
attachments. See also https://bugs.kde.org/show_bug.cgi?id=340312 

The bug seems to be fixed in 4.14.12 according to this bug report.


--- System information. ---
Architecture: amd64
Kernel:       Linux 3.16.0-4-amd64

Debian Release: stretch/sid
  500 testing         www.deb-multimedia.org 
  500 testing         security.debian.org 
  500 testing         ftp5.gwdg.de 

--- Package information. ---
Package's Depends field is empty.

Package's Recommends field is empty.

Package's Suggests field is empty.
-- 
Max-Planck-Institute for Dynamics and Self-Organization
Research Group Biomedical Physics

Am Fassberg 17
D-37077 Goettingen
(+49) 551 5176 373

You can obtain my public key 0xF197B128 from all keyservers, e.g. pgp.mit.edu
Fingerprint: 9698 BDD4 71CC 1274 B7E2  2049 1EDD 012D F197 B128
[signature.asc (application/pgp-signature, inline)]

Set Bug forwarded-to-address to 'https://bugs.kde.org/show_bug.cgi?id=340312'. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Tue, 14 Jul 2015 18:39:04 GMT) (full text, mbox, link).


Changed Bug title to 'kmail: CVE-2014-8878: Attachments are not encrypted when "automatic encryption" is selected"' from '[kmail] Attachments are not encrypted when "automatic encryption" is selected' Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Fri, 17 Jul 2015 03:15:03 GMT) (full text, mbox, link).


Added tag(s) fixed-upstream and upstream. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Fri, 17 Jul 2015 03:15:07 GMT) (full text, mbox, link).


Reply sent to Moritz Mühlenhoff <jmm@inutil.org>:
You have taken responsibility. (Fri, 06 May 2016 17:09:07 GMT) (full text, mbox, link).


Notification sent to Daniel Hornung <daniel.hornung@ds.mpg.de>:
Bug acknowledged by developer. (Fri, 06 May 2016 17:09:08 GMT) (full text, mbox, link).


Message #16 received at 791800-done@bugs.debian.org (full text, mbox, reply):

From: Moritz Mühlenhoff <jmm@inutil.org>
To: Daniel Hornung <daniel.hornung@ds.mpg.de>
Cc: 791800-done@bugs.debian.org
Subject: Re: [kmail] Attachments are not encrypted when "automatic encryption" is selected
Date: Fri, 6 May 2016 19:04:30 +0200
Version: 4:4.14.5-1

On Wed, Jul 08, 2015 at 04:17:17PM +0200, Daniel Hornung wrote:
> Package: kmail
> Version: 4:4.14.1-1
> Severity: important
> Tags: security
> X-Debbugs-CC: secure-testing-team@lists.alioth.debian.org
> 
> --- Please enter the report below this line. ---
> 
> Sending OpenPGP/MIME encrypted emails with attachments does not encrypt the 
> attachments. See also https://bugs.kde.org/show_bug.cgi?id=340312 

Fixed in https://quickgit.kde.org/?p=kdepim.git&a=commit&h=626c857eb30c0533a4de7836ee843caaa8c00a26
which ended up in the 4.14.4 upstream release.

Marking 4.14.5-1 as fixed as the next following Debian upload.

Cheers,
        Moritz



Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Sat, 04 Jun 2016 07:24:59 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 18:42:25 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.