[Evolution] Bug#749293: evolution discloses email contacts to gravatar

Christoph Anton Mitterer calestyo at scientia.net
Mon May 26 01:58:54 UTC 2014


Package: evolution
Version: 3.12.2-1
Severity: important
Tags: security upstream


Apparently Evolution silently introduced the "feature" of querying
Gravatar for images of your email contacts.

AFAICS this is on by default and I wouldn't have found a way to
disable it.

This basically discloses all of whom I have contact with to gravatar
or anyone on the wire...
Not so good.


Chris.



More information about the Pkg-evolution-maintainers mailing list