[Enigmail] CVE-2014-5369 - Enigmail 1.7.1 ?

2014-08-25 Thread Remi Collet
Hi, See https://bugzilla.redhat.com/1133373 CVE-2014-5369 mail with only Bcc recipients sent in plain text Report says this is fixed in 1.7.1, but this is not released. Any planed date ? (else I will have to pick the fix from SCM... which I will prefer to avoid) Or perhaps I miss something.

Re: [Enigmail] CVE-2014-5369 - Enigmail 1.7.1 ?

2014-08-25 Thread Olav Seyfarth
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 Hi Remi, Report says fixed in 1.7.1, but not released. Any planed date? working on it, no date fixed yet. else pick fix from SCM... which I will prefer to avoid For the meantime, you may uninstall your distro package, download the XPI from

Re: [Enigmail] CVE-2014-5369 - Enigmail 1.7.1 ?

2014-08-25 Thread Remi Collet
Le 25/08/2014 17:13, Olav Seyfarth a écrit : For the meantime, you may uninstall your distro package, download the XPI from the enigmail website and install it through TBs AddOn Manager. I'm the distro enigmail maintainer, so obviously not interested buy your proposal ;) And I don't

Re: [Enigmail] CVE-2014-5369 - Enigmail 1.7.1 ?

2014-08-25 Thread Olav Seyfarth
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 Hi Remi, I'm the distro enigmail maintainer, so ... Sorry, did not realise that. My answer was intended to help those suffering from problems with 1.7 to gap the time till 1.7.1 is released. Before 1.6 it was problematic to install other than