Discussion:
[Tickets #12886] Re: IMP leaks E-mail message viewed status via SVG remote images
(too old to reply)
n***@bugs.horde.org
2013-12-22 19:19:14 UTC
Permalink
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/12886
------------------------------------------------------------------------------
Ticket | 12886
Updated By | roshansemba+***@gmail.com
<roshansemba+***@gmail.com>
Summary | IMP leaks E-mail message viewed status via SVG remote
| images
Queue | IMP
Version | 6.1.6
Type | Bug
State | Unconfirmed
Priority | 3. High
Milestone |
Patch |
Owners |
n***@bugs.horde.org
2013-12-26 23:31:51 UTC
Permalink
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/12886
------------------------------------------------------------------------------
Ticket | 12886
Updated By | Michael Slusarz <***@horde.org>
Summary | IMP leaks E-mail message viewed status via SVG remote
| images
Queue | IMP
Version | 6.1.6
Type | Bug
-State | Unconfirmed
+State | Feedback
-Priority | 3. High
+Priority | 1. Low
Milestone |
Patch |
Owners |
------------------------------------------------------------------------------


Michael Slusarz <***@horde.org> (2013-12-26 16:31) wrote:

Can't reproduce. Viewing the e-mail doesn't load the SVG image
automatically (or anything, for that matter - meaning that IMP passes
the privacy tester check 100%).

FWIW, I'm using FF 26/Win 7.
--
bugs mailing list
Frequently Asked Questions: http://wiki.horde.org/FAQ
To unsubscribe, mail: bugs-***@lists.horde.org
n***@bugs.horde.org
2013-12-26 23:42:26 UTC
Permalink
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/12886
------------------------------------------------------------------------------
Ticket | 12886
Updated By | roshansemba+***@gmail.com
Summary | IMP leaks E-mail message viewed status via SVG remote
| images
Queue | IMP
Version | 6.1.6
Type | Bug
State | Feedback
Priority | 1. Low
Milestone |
Patch |
Owners |
------------------------------------------------------------------------------


roshansemba+***@gmail.com (2013-12-26 23:42) wrote:

I'm able to reproduce consistently using FF26 and Chrome 31 on Windows
7, as well as Chrome 32 on Ubuntu Linux. FF didn't have any
extensions installed, and the tests on Chrome were done using an
incognito window in which no extensions were enabled.

The only test which triggers is the "SVG inline with remote image" test.

For example: https://emailprivacytester.com/2af95e57fd721a41
--
bugs mailing list
Frequently Asked Questions: http://wiki.horde.org/FAQ
To unsubscribe, mail: bugs-***@lists.horde.org
n***@bugs.horde.org
2013-12-26 23:53:39 UTC
Permalink
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/12886
------------------------------------------------------------------------------
Ticket | 12886
Updated By | Michael Slusarz <***@horde.org>
Summary | IMP leaks E-mail message viewed status via SVG remote
| images
Queue | IMP
Version | 6.1.6
Type | Bug
State | Feedback
Priority | 1. Low
Milestone |
Patch |
Owners |
------------------------------------------------------------------------------
Post by n***@bugs.horde.org
I'm able to reproduce consistently using FF26 and Chrome 31 on
Windows 7, as well as Chrome 32 on Ubuntu Linux.
I'm not able to reproduce using ANY browser. On *multiple* different
OS's. (Win 7, Ubuntu 13, WinXP; Chrome, FF, IE, and Chromium).

https://emailprivacytester.com/bcccb9a686e0c162

So it sounds like something specific to your setup unless you can show
otherwise.
--
bugs mailing list
Frequently Asked Questions: http://wiki.horde.org/FAQ
To unsubscribe, mail: bugs-***@lists.horde.org
n***@bugs.horde.org
2013-12-27 00:08:30 UTC
Permalink
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/12886
------------------------------------------------------------------------------
Ticket | 12886
Updated By | roshansemba+***@gmail.com
Summary | IMP leaks E-mail message viewed status via SVG remote
| images
Queue | IMP
Version | 6.1.6
Type | Bug
State | Feedback
Priority | 1. Low
Milestone |
Patch |
Owners |
------------------------------------------------------------------------------
Post by n***@bugs.horde.org
I'm not able to reproduce using ANY browser. On *multiple*
different OS's. (Win 7, Ubuntu 13, WinXP; Chrome, FF, IE, and
Chromium).
I've just verified using IE11 on Win 7 as well, and see the same test
coming up red. That's four browsers, on two different computers.
Post by n***@bugs.horde.org
So it sounds like something specific to your setup unless you can
show otherwise.
Any suggestions you may have on what to look at are welcome. My
installation is fairly standard, running on an Ubuntu 12.04 server,
with the Horde installation done via Pear. I can try setting up a
completely new Horde/IMP installation, but that's the most extreme and
heavy next step for me.
--
bugs mailing list
Frequently Asked Questions: http://wiki.horde.org/FAQ
To unsubscribe, mail: bugs-***@lists.horde.org
n***@bugs.horde.org
2014-01-08 18:49:09 UTC
Permalink
DO NOT REPLY TO THIS MESSAGE. THIS EMAIL ADDRESS IS NOT MONITORED.

Ticket URL: http://bugs.horde.org/ticket/12886
------------------------------------------------------------------------------
Ticket | 12886
Updated By | Michael Slusarz <***@horde.org>
Summary | IMP leaks E-mail message viewed status via SVG remote
| images
Queue | IMP
Version | 6.1.6
Type | Bug
State | Feedback
Priority | 1. Low
Milestone |
Patch |
Owners |
------------------------------------------------------------------------------
Post by n***@bugs.horde.org
Any suggestions you may have on what to look at are welcome. My
installation is fairly standard, running on an Ubuntu 12.04 server,
with the Horde installation done via Pear.
Are you using the PHP package provided by Ubuntu? I believe that is
PHP 5.3.10. That is ancient. My guess is that your PHP is too old
(and or the libxml component) and some bug has been fixed since then
that is the root cause of this issue for you.

FWIW, I am running PHP 5.4.22 on my system (libxml 2.9.1).
--
bugs mailing list
Frequently Asked Questions: http://wiki.horde.org/FAQ
To unsubscribe, mail: bugs-***@lists.horde.org
Loading...