security alert: attachment filename "summary2004.txt .pif"

RESOLVED DUPLICATE of bug 186974

Status

SeaMonkey
MailNews: Message Display
--
critical
RESOLVED DUPLICATE of bug 186974
13 years ago
11 years ago

People

(Reporter: James Salsman, Unassigned)

Tracking

(Blocks: 1 bug)

1.7 Branch
x86
Windows XP

Firefox Tracking Flags

(Not tracked)

Details

(Reporter)

Description

13 years ago
When a filename wider than a certain number of characters, including spaces, is
displayed in the attachment window of the email message view, then "..." at the
right side is used to indicate that the file name is actually longer.  This is a
very small indicator.

Please advise a-priority junk rule authors that I will never consider a 
file with more than two spaces in a row ending in a dangerous extention 
to be anything ever than junk, and I believe all but the worm-curious 
agree with this position.

Also, please consider a more prominent indicator than "..." when the truncated
filename containes consecutive whitespace.

Reproduction of worms is ill-advised.  You may however mail yourself an
ordinary text file named "diagram.gif                                          
                           .exe" to understand the importance of this problem.

Comment 1

13 years ago
Dup of bug to put the elipsis in the middle, not end.
Group: security
Keywords: crash, dataloss, privacy
Whiteboard: DUPME
(Reporter)

Comment 2

13 years ago
Agreed, but I still wish we would enhance our a-priori junk rules to clobber a
worm now and then.  If the users don't like it, they can explicitly un-junk them.
(Reporter)

Comment 3

13 years ago
I can find no such bug asking elipses to be placed in the middle of cropped
filenames, and therefore, until such a duplicate is found, I am blocking bug
74697 with just that suggestion.

I continue to suggest that another bug needs to be filed establishing some
a-priori junk rules to blast such unfreindly attachments with the
recyccle-these-bits icon.
Blocks: 74697
Whiteboard: DUPME
Product: Browser → Seamonkey

Comment 4

13 years ago
related to Bug 254913

Updated

13 years ago
Assignee: sspitzer → mail

Comment 5

11 years ago
Duping to the RFE for ellipsis mid-name.  See bug 74697 comment 20 for why this really isn't a critical or security issue, at least not with the current file handling.
Status: NEW → RESOLVED
Last Resolved: 11 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 186974
You need to log in before you can comment on or make changes to this bug.