From nobody@FreeBSD.org  Thu Dec 16 13:28:44 2004
Return-Path: <nobody@FreeBSD.org>
Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125])
	by hub.freebsd.org (Postfix) with ESMTP id 85A0C16A4CE
	for <freebsd-gnats-submit@FreeBSD.org>; Thu, 16 Dec 2004 13:28:44 +0000 (GMT)
Received: from www.freebsd.org (www.freebsd.org [216.136.204.117])
	by mx1.FreeBSD.org (Postfix) with ESMTP id 6F78843D41
	for <freebsd-gnats-submit@FreeBSD.org>; Thu, 16 Dec 2004 13:28:44 +0000 (GMT)
	(envelope-from nobody@FreeBSD.org)
Received: from www.freebsd.org (localhost [127.0.0.1])
	by www.freebsd.org (8.13.1/8.13.1) with ESMTP id iBGDSgBH008323
	for <freebsd-gnats-submit@FreeBSD.org>; Thu, 16 Dec 2004 13:28:42 GMT
	(envelope-from nobody@www.freebsd.org)
Received: (from nobody@localhost)
	by www.freebsd.org (8.13.1/8.13.1/Submit) id iBGDSggV008322;
	Thu, 16 Dec 2004 13:28:42 GMT
	(envelope-from nobody)
Message-Id: <200412161328.iBGDSggV008322@www.freebsd.org>
Date: Thu, 16 Dec 2004 13:28:42 GMT
From: Ilya Zhuravlev <i.a.zhuravlev@cbtnet.ru>
To: freebsd-gnats-submit@FreeBSD.org
Subject: Authentification data leak in emails sent to addressees (Evolution 2.0.2)
X-Send-Pr-Version: www-2.3

>Number:         75150
>Category:       ports
>Synopsis:       mail/evolution: Authentification data leak in emails sent to addressees (Evolution 2.0.2)
>Confidential:   no
>Severity:       serious
>Priority:       low
>Responsible:    gnome
>State:          closed
>Quarter:        
>Keywords:       
>Date-Required:  
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Thu Dec 16 13:30:28 GMT 2004
>Closed-Date:    Tue Jan 18 01:18:06 GMT 2005
>Last-Modified:  Tue Jan 18 01:18:06 GMT 2005
>Originator:     Ilya Zhuravlev
>Release:        5.3 release p1
>Organization:
None
>Environment:
FreeBSD host.cbtnet.ru 5.3-RELEASE-p1 FreeBSD 5.3-RELEASE-p1 #5: Tue Dec 14 13:36:59 IRKT 2004     ilya@crux.cbtnet.ru:/usr/src/sys/i386/compile/CRUX  i386      
>Description:
X-Mailer: Evolution 2.0.2 FreeBSD GNOME Team Port 
X-Evolution-Transport:smtp://i.a.zhuravlev%40cbtnet.ru;auth=PLAIN@mail.cbtnet.ru/;use_ssl=when-possible
X-Evolution-Account: Personal
----------------------------
This problem was discussed with developers of the program :
http://support-forums.novell.com/group/novell.support.evolution/readerNoFrame.tpt/@thread@175@F@10@D-,D@ALL/@article@172
(See "Unwanted feature in Evolution")
They assert, that did not include similar "functionality" in the Evolution.

>How-To-Repeat:
Sent email
>Fix:
Now X-headers are rewtitten on mail server
>Release-Note:
>Audit-Trail:
State-Changed-From-To: open->feedback 
State-Changed-By: vs 
State-Changed-When: Thu Dec 16 16:27:55 GMT 2004 
State-Changed-Why:  
Can you please elaborate on what you expect us to do? 
Is this a vulnerability we should list? 
Also please note that the port is already at 2.0.3. 


Responsible-Changed-From-To: freebsd-ports-bugs->gnome 
Responsible-Changed-By: vs 
Responsible-Changed-When: Thu Dec 16 16:27:55 GMT 2004 
Responsible-Changed-Why:  
Over to GNOME-team 

http://www.freebsd.org/cgi/query-pr.cgi?pr=75150 
State-Changed-From-To: feedback->closed 
State-Changed-By: marcus 
State-Changed-When: Tue Jan 18 01:17:49 GMT 2005 
State-Changed-Why:  
Feedback timeout from submitter. 

http://www.freebsd.org/cgi/query-pr.cgi?pr=75150 
>Unformatted:
