Open Bug 346434 Opened 18 years ago Updated 2 years ago

bogus Reply-To: field displayed in incoming mail

Categories

(Thunderbird :: Mail Window Front End, defect)

x86
Windows XP
defect

Tracking

(Not tracked)

People

(Reporter: chofmann, Unassigned)

References

(Blocks 1 open bug)

Details

(Keywords: testcase, Whiteboard: [STR comment 5])

Attachments

(6 files)

received some mail from costco and viewed the message.  then viewed other messages and it looks like the Reply-To: address has kept the costco address.

Hitting reply all other message seems to address the mail to the right address (I think, and I hope) but it looks pretty alarming.

will attach screenshot.
What version of TB was this bug reported against?

Are there extensions installed, and if so, does the symptom persist while running in Safe Mode?
Assignee: mscott → nobody
Attachment #231234 - Attachment description: note costco in Reply To: → Screenshot1: note bogus Reply-To header ("costco") from unrelated msg
Attachment #231235 - Attachment description: correct addressing as the result of hitting "reply all" → Screenshot2: correct recipients (without "costco") after "reply all" on msg of Screenshot1 that showed bogus reply-to in msg reader
Attachment #231234 - Attachment description: Screenshot1: note bogus Reply-To header ("costco") from unrelated msg → Screenshot1: Message B: note bogus Reply-To header ("costco") from unrelated Message A (previously viewed)
Attachment #231235 - Attachment description: Screenshot2: correct recipients (without "costco") after "reply all" on msg of Screenshot1 that showed bogus reply-to in msg reader → Screenshot2: correct recipients (without "costco") after "reply all" on Message B of Screenshot1 that showed bogus reply-to in msg reader
Attachment #231236 - Attachment description: message source of the mail from costco that might have generated the problem → Testcase1.eml: Message A with "Reply-To" header ("costco") that persisted for Message B (mail from "costco" that might have generated the problem; note that Reply-To and From are identical)
STR:

1) view Message A aka Testcase1.eml from attachment 231236 [details], which has these headers:
Reply-To: "Costco News" <CostcoNews#@#online.costco.com>
From: "Costco News" <CostcoNews#@#online.costco.com>

2) view another msg like Message B
a) probably without Reply-To header
b) or perhaps with identical From and Reply-To header

3) "Reply-all" to Message B

Actual result:

2) see Screenshot1 from attachment 231234 [details] (this bug):
Message B showing bogus Reply-To header wrongly persisted from Message A ("Costco News") in message reader preview pane

3) "Reply-all" to Message B acting correctly (not using the bogus Reply-To as a recipient)

Expected result:

2) Message B should not show/persist bogus Reply-To header from Message A
This should be re-tested with STR from comment 5.
I'd expect this to be wfm as I don't see any duplicates nor comments.
Whiteboard: [STR comment 5]
Keywords: qawanted
Attached file third.eml resets

The display bug is still present in the current version of Thunderbird 60.8.0 x64 Windows.

Three reduced samples are attached. first.eml triggers te problem, second can be used to show the problem, a third message can be used to reset.

It affects not only Reply-To, but als other headers such as To, Cc, Bcc and From if these are not present in the second message.

It appears that the first message and second message need to have a Sender header to cause these wrong headers being displayed. In the first message, the Sender headers needs to appear after the affected headers. In the second message, the location of the Sender header is not relevant.

I've updated to Thunderbird 68.0 x86 Windows

My samples do not exhibit the problems described in comment #10.

I checked testcase1.eml. It does not show a reply-to header at all. Just From, Subject, To. Even when set to "all headers" (View, Headers, All), it displays some of the headers but not Reply-to header.

It seems that for display, Thunderbird selects headers if there are many and it no longer considers Reply-To to be important.
I think it is important to know before hitting reply to which address it will be send even though it will show in the reply message. Not showing has security implications e.g. in scams and phishing. These messages often forge the sender address and they use a different Reply-to address.

Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: