Reply sometimes randomly appends unrelated message below quoted message

Bug #1033584 reported by B Bobo
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
thunderbird (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

When displaying an email in Thunderbird, hitting the Reply button opens a new window containing a quoted version of the email you are replying to. That is what you expect to happen. However, rarely and intermittently in the same reply window, an unquoted version of the body of the most recently written email appears underneath the quoted email you are replying to.

There is no clear pattern as to when it happens. It has been happening intermittently in all versions of Thunderbird from the 14.0 in Precise 12.04 to whatever version it was in Lucid 10.04. The Thunderbird error log / console is usually empty when it happens. It has happened in plain Thunderbird with the default Ubuntu theme version 14.0 and without any addons. Some kind of paste buffer management is going wrong and picking up a copy of a previous message (but it happens even without using cut-and-paste)?

Here is an example of how it looks after hitting the Reply button while displaying an email from <email address hidden>:
This is meant to be a reply to JaneL's email, but notice there is an unwanted copy of the body of another recently written email to John that has been appended as one line of plain text underneath the quoted version of JaneL's email.
This unwanted appending is very easy not to notice, meaning there is a real risk of accidentally passing on unrelated email to unintended recipients, creating a breach of privacy or worse, which is a security issue for those involved. Please investigate and fix.

On 06/08/12 11:30, <email address hidden> wrote:
> Hi Bob,
> Yes!! 5pm is ok. See you!
> xox J.
John, our afternoon meeting is off, please reschedule for 9am. Bob

Revision history for this message
Jamie Strandboge (jdstrand) wrote : Bug is not a security issue

Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privilege boundaries nor directly cause loss of data/privacy. Please feel free to report any other bugs you may find.

security vulnerability: yes → no
visibility: private → public
Revision history for this message
Erno Kuusela (erno-iki) wrote :

It's obviously a security bug from the user's point of view. It breaks the "C" in the traditional C-I-A (confidentiality/integrity/availability) definition of infosec.

See also: http://cwe.mitre.org/data/definitions/200.html

Revision history for this message
B Bobo (yout-bobo123) wrote :

@Jamie, I don't think the reasoning behind your analysis is correct. Thunderbird is randomly copying and pasting the contents of recently written emails onto the end of new emails to unrelated third parties. Per Erno's explanation above, this is a security issue. Leaking of confidential or private information to unapproved third parties is always a security issue in any context.

Even worse, the leaking by Thunderbird is being done so stealthily.

It is incredible that this bug exists in a very prominent email application such as Thunderbird. It needs to be fixed urgently.

tags: added: security
B Bobo (yout-bobo123)
information type: Public → Public Security
Changed in mozilla-thunderbird (Ubuntu):
status: New → Triaged
Mathew Hodson (mhodson)
affects: mozilla-thunderbird (Ubuntu) → thunderbird (Ubuntu)
Revision history for this message
Paul White (paulw2u) wrote :

Reporter no longer uses Launchpad and is not subscribed to bug report
Issue seen "rarely and intermittently", not confirmed by another user
Nothing found upstream, open or closed
No comments here for over 6 years so closing

Changed in thunderbird (Ubuntu):
status: Triaged → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.