Mike Kupfer
2014-11-30 17:48:21 UTC
---
** [bugs:#478] shr image fetching should be disabled by default**
**Status:** unread
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Sun Nov 30, 2014 05:48 PM UTC
**Owner:** nobody
The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.
This means that an MH-E user who is using shr is vulnerable to web bugs.
MH-E 8.6
MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13
GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro
nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh
Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux
---
Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/
To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
** [bugs:#478] shr image fetching should be disabled by default**
**Status:** unread
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Sun Nov 30, 2014 05:48 PM UTC
**Owner:** nobody
The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.
This means that an MH-E user who is using shr is vulnerable to web bugs.
MH-E 8.6
MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13
GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro
nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh
Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux
---
Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/
To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.