Closed
Bug 295650
Opened 20 years ago
Closed 16 years ago
invalid from header could bypass remote image blocker
Categories
(Thunderbird :: Security, defect)
Tracking
(Not tracked)
RESOLVED
WORKSFORME
People
(Reporter: mscott, Unassigned)
Details
Found this interesting post in mozilla zine but I haven't tried it out yet: While it works fine when the "From" address is valid, I have received junk mail with From: "ALU OPRITTEN" <> in the message header and a remote image link in the body. The image is displayed even though this invalid address does not appear in my Personal Address Book. If I uncheck the option Allow remote images if the sender is in my: Personal Address Book The image is not displayed any more.
| Reporter | ||
Updated•20 years ago
|
Target Milestone: --- → Thunderbird1.1
| Reporter | ||
Comment 1•20 years ago
|
||
I replaced several messages to have a From header of: "ALU OPRITTEN" <> and was unable to reproduce this problem. We still blocked the remote images from loading. Maybe you have an empty address book card in your AB or something?
Comment 2•20 years ago
|
||
xref bug 232388 -- patch at bug 202169.
| Reporter | ||
Comment 3•20 years ago
|
||
moving off the 1.1 list since I was unable to reproduce this.
Target Milestone: Thunderbird1.1 → ---
Updated•18 years ago
|
QA Contact: front-end
Updated•16 years ago
|
Assignee: mscott → nobody
Component: Mail Window Front End → Security
Keywords: qawanted
QA Contact: front-end → thunderbird
You need to log in
before you can comment on or make changes to this bug.
Description
•