--- /dev/null
+Return-Path: <pieter@praet.org>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+ by olra.theworths.org (Postfix) with ESMTP id 1A6C6431FD4\r
+ for <notmuch@notmuchmail.org>; Fri, 3 Feb 2012 02:26:30 -0800 (PST)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: -0.7\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=-0.7 tagged_above=-999 required=5\r
+ tests=[RCVD_IN_DNSWL_LOW=-0.7] autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+ by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+ with ESMTP id 2vCNlTqpRWvo for <notmuch@notmuchmail.org>;\r
+ Fri, 3 Feb 2012 02:26:28 -0800 (PST)\r
+Received: from mail-ww0-f45.google.com (mail-ww0-f45.google.com\r
+ [74.125.82.45]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client\r
+ certificate requested) by olra.theworths.org (Postfix) with ESMTPS id\r
+ 243A0431FC0 for <notmuch@notmuchmail.org>; Fri, 3 Feb 2012 02:26:23 -0800\r
+ (PST)\r
+Received: by wgbdt12 with SMTP id dt12so3184622wgb.2\r
+ for <notmuch@notmuchmail.org>; Fri, 03 Feb 2012 02:26:22 -0800 (PST)\r
+Received: by 10.216.138.149 with SMTP id a21mr1530906wej.0.1328264782831;\r
+ Fri, 03 Feb 2012 02:26:22 -0800 (PST)\r
+Received: from localhost ([109.131.13.166])\r
+ by mx.google.com with ESMTPS id g6sm10951491wig.9.2012.02.03.02.26.22\r
+ (version=TLSv1/SSLv3 cipher=OTHER);\r
+ Fri, 03 Feb 2012 02:26:22 -0800 (PST)\r
+From: Pieter Praet <pieter@praet.org>\r
+To: David Bremner <david@tethera.net>\r
+Subject: [PATCH v6 2/3] emacs: quote MML tags in replies\r
+Date: Fri, 3 Feb 2012 11:24:08 +0100\r
+Message-Id: <1328264649-27346-2-git-send-email-pieter@praet.org>\r
+X-Mailer: git-send-email 1.7.8.1\r
+In-Reply-To: <87r4yc2p3y.fsf@praet.org>\r
+References: <87r4yc2p3y.fsf@praet.org>\r
+MIME-Version: 1.0\r
+Content-Type: text/plain; charset=UTF-8\r
+Content-Transfer-Encoding: 8bit\r
+Cc: Notmuch Mail <notmuch@notmuchmail.org>\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+ <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+ <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+ <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Fri, 03 Feb 2012 10:26:30 -0000\r
+\r
+From: Aaron Ecay <aaronecay@gmail.com>\r
+\r
+Emacs message-mode uses certain text strings to indicate how to attach\r
+files to outgoing mail. If these are present in the text of an email,\r
+and a user is tricked into replying to the message, the user’s files\r
+could be exposed.\r
+\r
+Edited-by: Pieter Praet <pieter@praet.org>: Rebased to release branch.\r
+---\r
+ NEWS | 11 +++++++++++\r
+ emacs/notmuch-mua.el | 7 ++++++-\r
+ test/emacs | 1 -\r
+ 3 files changed, 17 insertions(+), 2 deletions(-)\r
+\r
+diff --git a/NEWS b/NEWS\r
+index 3d2c2a8..a089e67 100644\r
+--- a/NEWS\r
++++ b/NEWS\r
+@@ -11,6 +11,17 @@ Fix error handling in python bindings.\r
+ exceptions to indicate the error condition. Any subsequent calls\r
+ into libnotmuch caused segmentation faults.\r
+ \r
++Quote MML tags in replies\r
++\r
++ MML tags are text codes that Emacs uses to indicate attachments\r
++ (among other things) in messages being composed. The Emacs\r
++ interface did not quote MML tags in the quoted text of a reply.\r
++ User could be tricked into replying to a maliciously formatted\r
++ message and not editing out the MML tags from the quoted text. This\r
++ could lead to files from the user's machine being attached to the\r
++ outgoing message. The Emacs interface now quotes these tags in\r
++ reply text, so that they do not effect outgoing messages.\r
++\r
+ \r
+ Notmuch 0.11 (2012-01-13)\r
+ =========================\r
+diff --git a/emacs/notmuch-mua.el b/emacs/notmuch-mua.el\r
+index 7114e48..3e93d7c 100644\r
+--- a/emacs/notmuch-mua.el\r
++++ b/emacs/notmuch-mua.el\r
+@@ -111,7 +111,12 @@ list."\r
+ (insert body))\r
+ (set-buffer-modified-p nil)\r
+ \r
+- (message-goto-body))\r
++ (message-goto-body)\r
++ ;; Original message may contain (malicious) MML tags. We must\r
++ ;; properly quote them in the reply. Note that using `point-max'\r
++ ;; instead of `mark' here is wrong. The buffer may include user's\r
++ ;; signature which should not be MML-quoted.\r
++ (mml-quote-region (point) (point-max)))\r
+ \r
+ (defun notmuch-mua-forward-message ()\r
+ (message-forward)\r
+diff --git a/test/emacs b/test/emacs\r
+index db8e4ad..2d066ed 100755\r
+--- a/test/emacs\r
++++ b/test/emacs\r
+@@ -274,7 +274,6 @@ EOF\r
+ test_expect_equal_file OUTPUT EXPECTED\r
+ \r
+ test_begin_subtest "Quote MML tags in reply"\r
+-test_subtest_known_broken\r
+ message_id='test-emacs-mml-quoting@message.id'\r
+ add_message [id]="$message_id" \\r
+ "[subject]='$test_subtest_name'" \\r
+-- \r
+1.7.8.1\r
+\r