Discussion:
[mh-e:bugs] #478 shr image fetching should be disabled by default
Mike Kupfer
2014-11-30 17:48:21 UTC
Permalink
---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** unread
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Sun Nov 30, 2014 05:48 PM UTC
**Owner:** nobody

The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2014-11-30 17:49:36 UTC
Permalink
attached gnus.png (screenshot of Gnus displaying the message)


Attachment: gnus.png (62.1 kB; image/png)


---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** unread
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Sun Nov 30, 2014 05:48 PM UTC
**Owner:** nobody

The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2014-11-30 17:50:19 UTC
Permalink
screenshot of MH-E displaying the message


Attachment: MH-E before Gnus.png (45.5 kB; image/png)


---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** unread
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Sun Nov 30, 2014 05:49 PM UTC
**Owner:** nobody

The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2014-11-30 17:51:15 UTC
Permalink
interestingly enough, if I view the message in MH-E while I am viewing it in Gnus in another frame, the image is not displayed.


Attachment: MH-E during Gnus.png (44.9 kB; image/png)


---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** unread
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Sun Nov 30, 2014 05:50 PM UTC
**Owner:** nobody

The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2014-11-30 18:02:02 UTC
Permalink
Here is some additional information about how Gnus handles images, courtesy of Adam SjÞgren. Given that MH-E does not display images while Gnus is displaying the message, I suspect that Gnus sets one or more global control variables telling shr whether to fetch/display images. MH-E should do something similar.

[text from Adam starts here]
Hi Adam, shr apparently fetches images by default.
Not in Gnus on my machine.
... for email.
Let's dig a little further...
[...]
The default is to block images defined by gnus-block-private-groups,
which blocks anything but newsgroups:

[...]
... and if you just want to turn off all images in general, you can
change the variable gnus-inhibit-images:



---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** unread
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Sun Nov 30, 2014 05:51 PM UTC
**Owner:** nobody

The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2014-11-30 18:04:06 UTC
Permalink
- **status**: unread --> open



---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** open
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Sun Nov 30, 2014 06:02 PM UTC
**Owner:** nobody

The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2014-12-05 00:04:49 UTC
Permalink
- **assigned_to**: Mike Kupfer
- **Priority**: 5 --> 7
- **Comment**:

Raised the priority to 7 to reflect the privacy concern.



---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** open
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Sun Nov 30, 2014 06:04 PM UTC
**Owner:** Mike Kupfer

The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2014-12-29 23:08:29 UTC
Permalink
The function mm-shr has this code:

(if (and (boundp 'gnus-summary-buffer)
(bufferp gnus-summary-buffer)
(buffer-name gnus-summary-buffer))
(with-current-buffer gnus-summary-buffer
(setq shr-inhibit-images gnus-inhibit-images
shr-blocked-images (gnus-blocked-images)))

The variable shr-inhibit-images is undocumented.
The docstring for shr-blocked-images says
Images that have URLs matching this regexp will be blocked.
(gnus-blocked-images) returns nil when viewing a message via MH-E, apparently because gnus-newsgroup-name is nil. Looking at the gnus-block-private-groups, I think we want shr-blocked-images to be "." to block image loading.


---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** open
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Fri Dec 05, 2014 12:04 AM UTC
**Owner:** Mike Kupfer

The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2014-12-29 23:21:27 UTC
Permalink
Setting the shr-* variables from MH-E doesn't work, because mm-shr will reset them based on the gnus-* variables.



---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** open
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Mon Dec 29, 2014 11:08 PM UTC
**Owner:** Mike Kupfer

The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2014-12-29 23:36:31 UTC
Permalink
Setting gnus-blocked-images to "." works better than setting gnus-inhibit-images to t. This is because gnus-inhibit-images also blocks embedded images.


---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** open
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Mon Dec 29, 2014 11:21 PM UTC
**Owner:** Mike Kupfer

The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2015-11-28 20:31:13 UTC
Permalink
This issue is also tracked at http://debbugs.gnu.org/cgi/bugreport.cgi?bug=21650.

Sorry for letting this go for so long; I'll get back to working on it soon.


---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** open
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Mon Dec 29, 2014 11:36 PM UTC
**Owner:** Mike Kupfer
**Attachments:**

- [1](https://sourceforge.net/p/mh-e/bugs/478/attachment/1) (2.8 kB; application/octet-stream)


The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2016-02-05 01:46:46 UTC
Permalink
We're working with the Gnus developers to fix this in the mm layer (see http://debbugs.gnu.org/cgi/bugreport.cgi?bug=21650.). I'm leaving this bug open for now in case there are documentation changes that we want to make.


---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** open
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Sat Nov 28, 2015 08:31 PM UTC
**Owner:** Mike Kupfer
**Attachments:**

- [1](https://sourceforge.net/p/mh-e/bugs/478/attachment/1) (2.8 kB; application/octet-stream)


The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2016-02-28 03:17:03 UTC
Permalink
See also ticket #483.


---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** open
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Fri Feb 05, 2016 01:46 AM UTC
**Owner:** Mike Kupfer
**Attachments:**

- [1](https://sourceforge.net/p/mh-e/bugs/478/attachment/1) (2.8 kB; application/octet-stream)


The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2016-05-30 23:47:25 UTC
Permalink
The code changes were addressed by multiple changes in the Gnus sources, ending with

commit fa55da20db11fd09a30c6e5c2205565929aee30e
Author: Katsumi Yamaoka <***@jpl.org>
Date: Tue Feb 9 22:24:25 2016 +0000

Make mm-html-blocked-images default to "" again

* lisp/gnus/mm-decode.el (mm-html-blocked-images):
Default to "" that blocks all external images.

* doc/misc/emacs-mime.texi (Display Customization):
Mention that mm-html-blocked-images defaults to "".

The MH-E User Guide was updated with

commit 602bb40029525c14cb1429d4a521da552d3a583b
Author: Mike Kupfer <***@acm.org>
Date: Mon May 30 16:13:10 2016 -0700

Update MH-E's documentation about HTML renderers

* doc/misc/mh-e.texi (HTML): Remove the footnote with the minimum Gnus
version (we are no longer trying to support multiple Emacs
releases). Sort the table of HTML renderers by name (the previous
ordering was based on a 10-year-old survey). Add shr and gnus-w3m to
the table. Remove the entry for w3 (no longer available). Update
existing entries so that they are more consistent about what features
are discussed, and to reflect recent testing (Debian 8). Small tweaks
to existing text.

Closing.


---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** open
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Sun Feb 28, 2016 03:17 AM UTC
**Owner:** Mike Kupfer
**Attachments:**

- [1](https://sourceforge.net/p/mh-e/bugs/478/attachment/1) (2.8 kB; application/octet-stream)


The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Mike Kupfer
2016-05-30 23:47:51 UTC
Permalink
- **status**: open --> closed-fixed



---

** [bugs:#478] shr image fetching should be disabled by default**

**Status:** closed-fixed
**Milestone:** Unassigned
**Created:** Sun Nov 30, 2014 05:48 PM UTC by Mike Kupfer
**Last Updated:** Mon May 30, 2016 11:47 PM UTC
**Owner:** Mike Kupfer
**Attachments:**

- [1](https://sourceforge.net/p/mh-e/bugs/478/attachment/1) (2.8 kB; application/octet-stream)


The attached message ("1") has a reference to a remote image. If I set the mm-text-html-renderer to 'shr and view the message in Gnus, the image is not fetched or displayed. If I exit Gnus and then view the message in MH-E, the image *is* fetched and displayed.

This means that an MH-E user who is using shr is vulnerable to web bugs.

MH-E 8.6

MH-E compilation details:
Byte compiled: yes
Gnus (compile-time): Gnus v5.13
Gnus (run-time): Gnus v5.13

GNU Emacs 24.3.94.3 (x86_64-unknown-linux-gnu, X toolkit, Xaw scroll bars)
of 2014-11-01 on allegro

nmh 1.5
mh-progs: /usr/bin/mh
mh-lib: /etc/nmh
mh-lib-progs: /usr/lib/mh

Linux allegro 3.2.0-4-amd64 #1 SMP Debian 3.2.63-2+deb7u1 x86_64 GNU/Linux



---

Sent from sourceforge.net because mh-e-***@lists.sourceforge.net is subscribed to https://sourceforge.net/p/mh-e/bugs/

To unsubscribe from further messages, a project admin can change settings at https://sourceforge.net/p/mh-e/admin/bugs/options. Or, if this is a mailing list, you can unsubscribe from the mailing list.
Loading...