seahorse plugin in evolution decrypts files in .evolution and leaves them there!

Bug #176454 reported by zanonmark
262
This bug affects 1 person
Affects Status Importance Assigned to Milestone
seahorse
Unknown
High
seahorse-plugins
Confirmed
Wishlist
seahorse-plugins (Ubuntu)
Confirmed
Medium
Ubuntu Desktop Bugs

Bug Description

Binary package hint: seahorse

There is a serious security hole in the Seahorse plugin for Evolution.

When you click on an attachment and choose the "Decrypt file" option, it decrypts the file under ./.evolution/cache/tmp/evolution-tmp-XXXXXX, without noticing the user.
Once you close Evolution, the "clear" file remains there!

So
1) you did not read the attachment from Evolution (thus making this plugin useless), and
2) the "clear" attachment is still on the disk!

Thanks,

MZ

Revision history for this message
Andreas Moog (ampelbein) wrote :

Thank you for your report. Is this still an issue for you?

Changed in seahorse:
assignee: nobody → andreas-moog
importance: Undecided → Medium
status: New → Incomplete
Revision history for this message
zanonmark (info-marcozanon) wrote : Re: [Bug 176454] Re: seahorse plugin in evolution decrypts files in .evolution and leaves them there!

> Thank you for your report. Is this still an issue for you?

yes, it is: just checked now...

thanks :)

Marco

Revision history for this message
Andreas Moog (ampelbein) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better. I reported this issue upstream, you can track the status and make comments here:

http://bugzilla.gnome.org/show_bug.cgi?id=551235

Changed in seahorse:
assignee: andreas-moog → desktop-bugs
status: Incomplete → Triaged
Changed in seahorse:
status: Unknown → New
Changed in seahorse:
status: New → Invalid
Changed in seahorse-plugins:
status: Unknown → Confirmed
Changed in seahorse-plugins:
importance: Unknown → Wishlist
Changed in seahorse:
importance: Unknown → High
status: Invalid → Unknown
Changed in seahorse-plugins (Ubuntu):
status: Triaged → Confirmed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.