Bugzilla (bugzilla.redhat.com) will be under maintenance for infrastructure upgrades and will not be unavailable on July 31st between 12:30 AM - 05:30 AM UTC. We appreciate your understanding and patience. You can follow status.redhat.com for details.
Bug 1569181 - emacs RMAIL leaks internal information from GNUS
Summary: emacs RMAIL leaks internal information from GNUS
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: emacs
Version: 7.5
Hardware: Unspecified
OS: Unspecified
Target Milestone: rc
: ---
Assignee: Lukáš Nykrýn
QA Contact: qe-baseos-daemons
Depends On:
TreeView+ depends on / blocked
Reported: 2018-04-18 18:07 UTC by DJ Delorie
Modified: 2021-02-15 07:38 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2021-02-15 07:38:31 UTC
Target Upstream Version:

Attachments (Terms of Use)

Description DJ Delorie 2018-04-18 18:07:51 UTC
Description of problem:

If you use GNUS and RMAIL, replying to an email includes your most recent GNUS group in the headers, which should be considered sensitive company-confidential information:

To: "Somebody" <somebody>
Subject: Re: <redacted>
In-Reply-To: <redacted>
X-Draft-From: ("nntp+localhost:mail.redhat.<redacted>" 12345)
From: DJ Delorie <dj@redhat.com>
--text follows this line--

Version-Release number of selected component (if applicable):

RHEL 7.5
emacs 24.3-20.el7_4.x86_64

How reproducible:


Steps to Reproduce:
1. Read news via GNUS
2. Read mail via RMAIL
3. Reply to an email

Actual results:

X-Draft-From header is in reply.

Expected results:

X-Draft-From header is not in reply.

Additional info:

Bug still exists in emacs-25.3-3.fc26.x86_64

Comment 6 RHEL Program Management 2021-02-15 07:38:31 UTC
After evaluating this issue, there are no plans to address it further or fix it in an upcoming release.  Therefore, it is being closed.  If plans change such that this issue will be fixed in an upcoming release, then the bug can be reopened.

Note You need to log in before you can comment on or make changes to this bug.