[原文]Mail.app in Mail for Apple Mac OS X 10.3.9 and 10.4.2 includes message contents when using auto-reply rules, which could cause Mail.app to include decrypted message contents for encrypted messages.
Apple Mac OS X Mail.app auto-reply Rule Encrypted Message Cleartext Disclosure
Remote / Network Access
Loss of Confidentiality
Mac OS X contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when Mail.app processes an auto-reply rule for an encrypted message, which will include the decrypted contents of the original mail in the reply resulting in a loss of confidentiality.
Currently, there are no known workarounds or upgrades to correct this issue. However, Apple has released a patch (Security Update 2005-008) to address this vulnerability.