Bug 1569181

Summary: emacs RMAIL leaks internal information from GNUS
Product: Red Hat Enterprise Linux 7 Reporter: DJ Delorie <dj>
Component: emacsAssignee: Lukáš Nykrýn <lnykryn>
Status: CLOSED WONTFIX QA Contact: qe-baseos-daemons
Severity: high Docs Contact:
Priority: unspecified    
Version: 7.5CC: fsumsal
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-02-15 07:38:31 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description DJ Delorie 2018-04-18 18:07:51 UTC
Description of problem:

If you use GNUS and RMAIL, replying to an email includes your most recent GNUS group in the headers, which should be considered sensitive company-confidential information:

To: "Somebody" <somebody>
Subject: Re: <redacted>
In-Reply-To: <redacted>
X-Draft-From: ("nntp+localhost:mail.redhat.<redacted>" 12345)
From: DJ Delorie <dj>
--text follows this line--


Version-Release number of selected component (if applicable):

RHEL 7.5
emacs 24.3-20.el7_4.x86_64

How reproducible:

Always

Steps to Reproduce:
1. Read news via GNUS
2. Read mail via RMAIL
3. Reply to an email

Actual results:

X-Draft-From header is in reply.

Expected results:

X-Draft-From header is not in reply.

Additional info:

Bug still exists in emacs-25.3-3.fc26.x86_64

Comment 6 RHEL Program Management 2021-02-15 07:38:31 UTC
After evaluating this issue, there are no plans to address it further or fix it in an upcoming release.  Therefore, it is being closed.  If plans change such that this issue will be fixed in an upcoming release, then the bug can be reopened.