[PATCH v4 2/2] emacs: quote MML tags in replies
authorDavid Bremner <david@tethera.net>
Thu, 2 Feb 2012 04:01:33 +0000 (00:01 +2000)
committerW. Trevor King <wking@tremily.us>
Fri, 7 Nov 2014 17:43:55 +0000 (09:43 -0800)
2b/23fe3117965c35bc03eb4f88156afa653ef19a [new file with mode: 0644]

diff --git a/2b/23fe3117965c35bc03eb4f88156afa653ef19a b/2b/23fe3117965c35bc03eb4f88156afa653ef19a
new file mode 100644 (file)
index 0000000..a11761f
--- /dev/null
@@ -0,0 +1,127 @@
+Return-Path: <bremner@tethera.net>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+       by olra.theworths.org (Postfix) with ESMTP id 29874431FAF\r
+       for <notmuch@notmuchmail.org>; Wed,  1 Feb 2012 20:01:59 -0800 (PST)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: -2.3\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=-2.3 tagged_above=-999 required=5\r
+       tests=[RCVD_IN_DNSWL_MED=-2.3] autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+       by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+       with ESMTP id swv2QBQZEuE8 for <notmuch@notmuchmail.org>;\r
+       Wed,  1 Feb 2012 20:01:58 -0800 (PST)\r
+Received: from tempo.its.unb.ca (tempo.its.unb.ca [131.202.1.21])\r
+       (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))\r
+       (No client certificate requested)\r
+       by olra.theworths.org (Postfix) with ESMTPS id 8EAC7431FAE\r
+       for <notmuch@notmuchmail.org>; Wed,  1 Feb 2012 20:01:58 -0800 (PST)\r
+Received: from zancas.localnet\r
+       (fctnnbsc36w-156034071197.pppoe-dynamic.High-Speed.nb.bellaliant.net\r
+       [156.34.71.197]) (authenticated bits=0)\r
+       by tempo.its.unb.ca (8.13.8/8.13.8) with ESMTP id q1241u3A010872\r
+       (version=TLSv1/SSLv3 cipher=AES256-SHA bits=256 verify=NO);\r
+       Thu, 2 Feb 2012 00:01:56 -0400\r
+Received: from bremner by zancas.localnet with local (Exim 4.77)\r
+       (envelope-from <bremner@tethera.net>)\r
+       id 1Rsnrw-0003l2-I7; Thu, 02 Feb 2012 00:01:56 -0400\r
+From: David Bremner <david@tethera.net>\r
+To: notmuch@notmuchmail.org\r
+Subject: [PATCH v4 2/2] emacs: quote MML tags in replies\r
+Date: Thu,  2 Feb 2012 00:01:33 -0400\r
+Message-Id: <1328155293-2334-3-git-send-email-david@tethera.net>\r
+X-Mailer: git-send-email 1.7.8.3\r
+In-Reply-To: <1328155293-2334-1-git-send-email-david@tethera.net>\r
+References: <1328064581-13949-1-git-send-email-dmitry.kurochkin@gmail.com>\r
+       <1328155293-2334-1-git-send-email-david@tethera.net>\r
+MIME-Version: 1.0\r
+Content-Type: text/plain; charset=UTF-8\r
+Content-Transfer-Encoding: 8bit\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+       <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Thu, 02 Feb 2012 04:01:59 -0000\r
+\r
+From: Aaron Ecay <aaronecay@gmail.com>\r
+\r
+Emacs message-mode uses certain text strings to indicate how to attach\r
+files to outgoing mail.  If these are present in the text of an email,\r
+and a user is tricked into replying to the message, the user’s files\r
+could be exposed.\r
+\r
+Using point-max would include the signature in the quoting as well.\r
+It would probably be fairly odd to want to put an MML tag in one’s\r
+signature, but that doesn’t mean that we should break that usage.\r
+---\r
+ NEWS                 |   11 +++++++++++\r
+ emacs/notmuch-mua.el |    7 ++++++-\r
+ test/emacs           |    1 -\r
+ 3 files changed, 17 insertions(+), 2 deletions(-)\r
+\r
+diff --git a/NEWS b/NEWS\r
+index 3d2c2a8..a089e67 100644\r
+--- a/NEWS\r
++++ b/NEWS\r
+@@ -11,6 +11,17 @@ Fix error handling in python bindings.\r
+   exceptions to indicate the error condition. Any subsequent calls\r
+   into libnotmuch caused segmentation faults.\r
+ \r
++Quote MML tags in replies\r
++\r
++  MML tags are text codes that Emacs uses to indicate attachments\r
++  (among other things) in messages being composed.  The Emacs\r
++  interface did not quote MML tags in the quoted text of a reply.\r
++  User could be tricked into replying to a maliciously formatted\r
++  message and not editing out the MML tags from the quoted text.  This\r
++  could lead to files from the user's machine being attached to the\r
++  outgoing message.  The Emacs interface now quotes these tags in\r
++  reply text, so that they do not effect outgoing messages.\r
++\r
+ \r
+ Notmuch 0.11 (2012-01-13)\r
+ =========================\r
+diff --git a/emacs/notmuch-mua.el b/emacs/notmuch-mua.el\r
+index 7114e48..768b693 100644\r
+--- a/emacs/notmuch-mua.el\r
++++ b/emacs/notmuch-mua.el\r
+@@ -111,7 +111,12 @@ list."\r
+     (insert body))\r
+   (set-buffer-modified-p nil)\r
+ \r
+-  (message-goto-body))\r
++  (message-goto-body)\r
++  ;; Original message may contain (malicious) MML tags.  We must\r
++  ;; properly quote them in the reply.  Note that using `point-max'\r
++  ;; instead of `mark' here is wrong.  The buffer may include user's\r
++  ;; signature which should not be MML-quoted.\r
++  (mml-quote-region (point) (mark)))\r
+ \r
+ (defun notmuch-mua-forward-message ()\r
+   (message-forward)\r
+diff --git a/test/emacs b/test/emacs\r
+index 2a2ce28..de100c5 100755\r
+--- a/test/emacs\r
++++ b/test/emacs\r
+@@ -274,7 +274,6 @@ EOF\r
+ test_expect_equal_file OUTPUT EXPECTED\r
+ \r
+ test_begin_subtest "Quote MML tags in reply"\r
+-test_subtest_known_broken\r
+ message_id='test-emacs-mml-quoting@message.id'\r
+ add_message [id]="$message_id" \\r
+           "[subject]='$test_subtest_name'" \\r
+-- \r
+1.7.8.3\r
+\r