KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.
- http://bugs.kde.org/show_bug.cgi?id=96020
No PoCs found on GitHub currently.