[Kolab-devel] [issue1453] Specially crafter HTML Email can crash Kontact

Bernhard Reiter kolab-issues at intevation.de
Thu Oct 12 17:45:10 CEST 2006


New submission from Bernhard Reiter <bernhard at intevation.de>:

The attached email is reported to crash Kontact.  
http://www.securityfocus.com/bid/20369     
  
We got one user report, I will attach the traces.  
This most likely is with packages basing on KDE 3.4.  
  
My own reproduction failed so far:  
 Kontact: 1.0 (proko2 branch after 2.1.4), Revision 593832. 
Debian Sarge (ppc) with KDE: 3.3.2 Qt: 3.3.4 
 
Tried reproduce 
 
Configuration: Folder -> prefer HTML over plaintext 
 
a) File / Open 
        crashMail 
Could see the email: good. 
 
b) Extras-> Import message -> mbox 
Selected folder and message, could see it: good. 
 
c) looked at the message after changing the configuration 
   to _not_ prefer HTML and then clicking on the enabling pseudo-link

----------
assignedto: till
files: crashMail
messages: 8627
nosy: bernhard, bh, david, pradeepto, till
priority: critical
status: unread
title: Specially crafter HTML Email can crash Kontact
topic: kde client, kkc
________________________________________________
Kolab issue tracker <kolab-issues at intevation.de>
<https://intevation.de/roundup/kolab/issue1453>
________________________________________________
-------------- next part --------------
A non-text attachment was scrubbed...
Name: crashMail
Type: application/octet-stream
Size: 473 bytes
Desc: not available
URL: <http://lists.kolab.org/pipermail/devel/attachments/20061012/1b14bc9c/attachment.obj>


More information about the devel mailing list